Impact
The Listdom WordPress plugin contains an open redirect flaw that allows an attacker to craft a URL that forwards users to an arbitrary site without their knowledge. An affected WordPress installation can inadvertently direct visitors to phishing or malicious domains, potentially leading to credential theft or other social engineering attacks. This weakness is a classic open‑redirect vulnerability (CWE‑601).
Affected Systems
All installations of the Webilia Inc. Listdom plugin on WordPress that use version 4.0.0 or earlier are affected. The advisory does not specify any particular WordPress core versions, so the impact is confined to the plugin's code base.
Risk and Exploitability
The CVSS score of 4.7 indicates moderate severity, and the EPSS score of less than 1% suggests the exploitation probability is currently very low. The vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the flaw by persuading users to visit a crafted URL that triggers the plugin’s redirect mechanism; no authentication or privileged access is required, making phishing campaigns feasible from the compromised site.
OpenCVE Enrichment
EUVD