Impact
An Open Redirection flaw (CWE‑601) in the Newspack Newsletters plugin for WordPress allows an attacker to craft URLs that redirect users to arbitrary untrusted sites. The manipulation of redirection parameters can mislead users into visiting malicious pages, thereby facilitating phishing campaigns. The primary consequence is the loss of user trust and potential credential compromise, though no direct data theft or remote code execution is involved.
Affected Systems
WordPress sites utilizing the Automattic Newspack Newsletters plugin of version 3.13.0 or earlier are affected. Any instance where the plugin is enabled is vulnerable until an update is applied.
Risk and Exploitability
The CVSS score of 4.7 indicates moderate severity, while the EPSS score of less than 1% suggests low likelihood of current exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation typically requires a user to click a crafted link, implying that the attack vector is web‑based and relies on user interaction. Overall, the risk remains moderate, but vigilance is advised since phishing campaigns may target sites with the vulnerable plugin.
OpenCVE Enrichment
EUVD