{ "schema_version": "1.4.0", "id": "GHSA-mf96-763w-mh5v", "modified": "2022-01-29T00:01:03Z", "published": "2022-01-25T00:01:30Z", "aliases": [ "CVE-2021-25028" ], "details": "The Event Tickets WordPress plugin before 5.2.2 does not validate the tribe_tickets_redirect_to parameter before redirecting the user to the given value, leading to an arbitrary redirect issue", "severity": [], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-25028" }, { "type": "WEB", "url": "https://wpscan.com/vulnerability/80b0682e-2c3b-441b-9628-6462368e5fc7" } ], "database_specific": { "cwe_ids": [ "CWE-601" ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2022-01-24T08:15:00Z" } }