Impact
The User Registration & Membership WordPress plugin prior to version 5.2.8 fails to verify the target of a post-login redirect before performing the redirect. This omission permits an unauthenticated attacker to craft a link that redirects visitors to a malicious external URL immediately after a login attempt or form submission. The lack of validation can be exploited to facilitate phishing, social engineering, or drive traffic to malicious sites, potentially compromising user trust and privacy.
Affected Systems
The vulnerable component is the WordPress plugin User Registration & Membership. Any installation of the plugin with a version older than 5.2.8 is affected. No vendor name is specified; the plugin’s name and release provide sufficient identification for administrators to locate the correct update.
Risk and Exploitability
With a CVSS score of 4.7 the vulnerability is classified as moderate severity, and an EPSS score of 0.00171 indicates a low exploitation probability. It is not included in’s KEV catalog. Because the exploit requires no authentication and only manipulation of a URL parameter, the attack vector is a simple crafted link or email that redirects visitors to a malicious site. Although the direct impact on system integrity is limited, the potential damage lies in phishing-related credential theft, loss of user trust, and brand reputation damage when users are tricked into visiting compromised domains.
OpenCVE Enrichment