Impact
A URL redirection flaw in the Aculect AI Companion plugin permits an attacker to forward users to untrusted sites. The weakness allows a crafted request to trigger an open redirect, creating an avenue for phishing campaigns. This is a moderate severity issue (CVSS 4.7) classified under CWE-601. The vulnerability can compromise confidentiality by luring users to malicious domains.
Affected Systems
The vulnerability afflicts all WordPress installations of the Aculect AI Companion plugin up to and including version 0.8.1. No lower bound is specified, which implies that versions prior to 0.8.1 are also at risk unless patched.
Risk and Exploitability
The CVSS score of 4.7 indicates moderate risk, and the EPSS score is not available. The vulnerability is not listed in CISA's KEV catalog. Attackers likely exploit it by distributing a short link that redirects unsuspecting users to phishing sites. No special conditions are required beyond the presence of the vulnerable plugin; a publicly reachable site with the plugin installed is sufficient.
OpenCVE Enrichment