Description
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in GoodBarber GoodBarber goodbarber.This issue affects GoodBarber: from n/a through <= 1.0.26.
Published: 2025-09-09
Score: 4.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The GoodBarber plugin contains an open redirection flaw (CWE-601) that allows an attacker to craft URLs which, when clicked by a visitor, redirect the user to an arbitrary untrusted site. This can be used to facilitate phishing, drive users to malicious landing pages, or prime them for further attacks, though it does not grant code execution or direct system compromise. The impact is therefore limited to user deception and loss of trust rather than direct integrity or availability damage.

Affected Systems

The flaw exists in GoodBarber GoodBarber plugin versions from the earliest release through version 1.0.26. Any installation of the plugin in these versions is vulnerable. No other vendors or product lines are listed as affected.

Risk and Exploitability

The CVSS score of 4.7 rates the vulnerability as medium severity; however the EPSS score of less than 1% indicates a very low likelihood of exploitation at this time. The vulnerability is not present in the CISA KEV catalog. The attack vector is likely user‑directed; an attacker must supply or embed the malicious URL in a context that a user may click, such as emails or third‑party sites.

Generated by OpenCVE AI on April 30, 2026 at 15:16 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the GoodBarber plugin to the latest version (1.0.27 or newer).
  • If an update cannot be performed, disable or remove the redirect functionality within the plugin or block outbound redirect URLs at the web‑application level.
  • Implement outbound URL validation or sanitizer to ensure only trusted domains are allowed.

Generated by OpenCVE AI on April 30, 2026 at 15:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-27445 URL Redirection to Untrusted Site ('Open Redirect') vulnerability in GoodBarber GoodBarber. This issue affects GoodBarber: from n/a through 1.0.26.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description URL Redirection to Untrusted Site ('Open Redirect') vulnerability in GoodBarber GoodBarber. This issue affects GoodBarber: from n/a through 1.0.26. URL Redirection to Untrusted Site ('Open Redirect') vulnerability in GoodBarber GoodBarber goodbarber.This issue affects GoodBarber: from n/a through <= 1.0.26.
References
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N'}


Tue, 09 Sep 2025 23:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 09 Sep 2025 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Goodbarber
Goodbarber goodbarber
Wordpress
Wordpress wordpress
Vendors & Products Goodbarber
Goodbarber goodbarber
Wordpress
Wordpress wordpress

Tue, 09 Sep 2025 16:45:00 +0000

Type Values Removed Values Added
Description URL Redirection to Untrusted Site ('Open Redirect') vulnerability in GoodBarber GoodBarber. This issue affects GoodBarber: from n/a through 1.0.26.
Title WordPress GoodBarber plugin <= 1.0.26 - Open Redirection Vulnerability
Weaknesses CWE-601
References
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N'}


Subscriptions

Goodbarber Goodbarber
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:34.027Z

Reserved: 2025-04-16T06:24:32.684Z

Link: CVE-2025-39523

cve-icon Vulnrichment

Updated: 2025-09-09T17:49:44.207Z

cve-icon NVD

Status : Deferred

Published: 2025-09-09T17:15:45.290

Modified: 2026-04-23T15:29:43.447

Link: CVE-2025-39523

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T15:30:16Z

Weaknesses