Description
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Arthur Yarwood Fast eBay Listings fast-ebay-listings allows Phishing.This issue affects Fast eBay Listings: from n/a through <= 2.12.15.
Published: 2025-04-16
Score: 4.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Fast eBay Listings plugin contains a flaw that allows an authenticated or unauthenticated party to direct users to an external, untrusted URL. This open redirect vulnerability, identified as CWE‑601, enables attackers to move site visitors to malicious domains such as phishing pages, potentially compromising credentials or installing malware. The impact is limited to the integrity of user navigation and the confidentiality of information that users may supply after being led to a malicious site.

Affected Systems

The vulnerability affects the Arthur Yarwood Fast eBay Listings WordPress plugin. All releases up to, and including, version 2.12.15 are impacted. No other product or version information is listed.

Risk and Exploitability

The CVSS score of 4.7 indicates moderate severity, while the EPSS score of less than 1% suggests a low probability of exploitation. The issue is not currently listed in the CISA KEV catalog, consistent with its low exploit likelihood. Exploitation would typically involve a user clicking a manipulated link within the affected plugin, which then redirects the user to an attacker‑controlled domain. An attacker could then attempt credential harvesting or deliver malware. Because the attack vector is via normal site usage and no privileged access is required, the risk is primarily to end users rather than the server itself.

Generated by OpenCVE AI on April 30, 2026 at 22:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Fast eBay Listings plugin to the latest available release that removes the redirect flaw.
  • If an immediate upgrade is not possible, modify the plugin’s redirect handling to allow only URLs that match a whitelist of approved domains.
  • Regularly audit outbound redirects in the site’s plugins and block or rate‑limit suspicious redirects to prevent phishing attempts.

Generated by OpenCVE AI on April 30, 2026 at 22:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-11300 URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Arthur Yarwood Fast eBay Listings allows Phishing. This issue affects Fast eBay Listings: from n/a through 2.12.15.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Arthur Yarwood Fast eBay Listings allows Phishing. This issue affects Fast eBay Listings: from n/a through 2.12.15. URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Arthur Yarwood Fast eBay Listings fast-ebay-listings allows Phishing.This issue affects Fast eBay Listings: from n/a through <= 2.12.15.
Title WordPress Fast eBay Listings <= 2.12.15 - Open Redirection Vulnerability WordPress Fast eBay Listings plugin <= 2.12.15 - Open Redirection Vulnerability
References
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N'}


Wed, 16 Apr 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Apr 2025 12:45:00 +0000

Type Values Removed Values Added
Description URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Arthur Yarwood Fast eBay Listings allows Phishing. This issue affects Fast eBay Listings: from n/a through 2.12.15.
Title WordPress Fast eBay Listings <= 2.12.15 - Open Redirection Vulnerability
Weaknesses CWE-601
References
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-05-12T00:07:39.077Z

Reserved: 2025-04-16T06:26:52.003Z

Link: CVE-2025-39597

cve-icon Vulnrichment

Updated: 2025-04-16T14:11:32.915Z

cve-icon NVD

Status : Deferred

Published: 2025-04-16T13:15:52.217

Modified: 2026-04-23T15:29:51.690

Link: CVE-2025-39597

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T23:00:04Z

Weaknesses