Description
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Bit Apps Bit Integrations bit-integrations allows Phishing.This issue affects Bit Integrations: from n/a through <= 2.4.10.
Published: 2025-03-27
Score: 4.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An Open Redirect vulnerability exists in Bit Apps Bit Integrations versions up to 2.4.10 that allows an attacker to redirect users to malicious, untrusted sites, thereby facilitating phishing attacks. The weakness maps to CWE-601 and results in a loss of control over where users are directed while they interact with the site.

Affected Systems

The Bit Apps Bit Integrations WordPress plugin, from its earliest released version through 2.4.10 inclusive, is vulnerable. All sites running any of these versions are at risk.

Risk and Exploitability

With a CVSS score of 4.7, the vulnerability is considered medium severity, and the EPSS score of less than 1% indicates a low probability of exploitation at this time; the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a lure link that redirects a user to a malicious site, inferred from the described phishing potential and the nature of open redirects when no explicit restriction is applied to user-supplied URLs.

Generated by OpenCVE AI on May 1, 2026 at 03:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Bit Integrations plugin to the latest version available (≥2.4.11) to eliminate the open redirect flaw.
  • Disable or remove unnecessary redirect functionality within the plugin or block access to redirect endpoints if they are not essential for site operation.
  • Implement input validation or URL whitelisting on the server side to ensure only approved destinations can be accessed via redirects.
  • Monitor web server logs for anomalous redirect patterns and apply IP blocking or rate limiting against suspicious activity.

Generated by OpenCVE AI on May 1, 2026 at 03:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-8319 URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Bit Apps Bit Integrations allows Phishing. This issue affects Bit Integrations: from n/a through 2.4.10.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Bit Apps Bit Integrations allows Phishing. This issue affects Bit Integrations: from n/a through 2.4.10. URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Bit Apps Bit Integrations bit-integrations allows Phishing.This issue affects Bit Integrations: from n/a through <= 2.4.10.
References
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N'}


Thu, 27 Mar 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 27 Mar 2025 11:00:00 +0000

Type Values Removed Values Added
Description URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Bit Apps Bit Integrations allows Phishing. This issue affects Bit Integrations: from n/a through 2.4.10.
Title WordPress Bit Integrations plugin <= 2.4.10 - Open Redirection vulnerability
Weaknesses CWE-601
References
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:59.782Z

Reserved: 2025-03-26T09:21:23.220Z

Link: CVE-2025-30884

cve-icon Vulnrichment

Updated: 2025-03-27T17:42:46.236Z

cve-icon NVD

Status : Deferred

Published: 2025-03-27T11:15:49.357

Modified: 2026-04-23T15:27:15.633

Link: CVE-2025-30884

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T04:00:06Z

Weaknesses