Vulnerability Details CVE-2021-25102
The All In One WP Security & Firewall WordPress plugin before 4.4.11 does not validate, sanitise and escape the redirect_to parameter before using it to redirect user, either via a Location header, or meta url attribute, when the Rename Login Page is active, which could lead to an Arbitrary Redirect as well as Cross-Site Scripting issue. Exploitation of this issue requires the Login Page URL value to be known, which should be hard to guess, reducing the risk
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 42.4%
CVSS Severity
CVSS v3 Score 4.7
CVSS v2 Score 2.6
Products affected by CVE-2021-25102
-
cpe:2.3:a:tipsandtricks-hq:all_in_one_wp_security_&_firewall:-
-
cpe:2.3:a:tipsandtricks-hq:all_in_one_wp_security_&_firewall:1.0
-
cpe:2.3:a:tipsandtricks-hq:all_in_one_wp_security_&_firewall:1.1
-
cpe:2.3:a:tipsandtricks-hq:all_in_one_wp_security_&_firewall:1.2
-
cpe:2.3:a:tipsandtricks-hq:all_in_one_wp_security_&_firewall:1.3
-
cpe:2.3:a:tipsandtricks-hq:all_in_one_wp_security_&_firewall:1.4
-
cpe:2.3:a:tipsandtricks-hq:all_in_one_wp_security_&_firewall:1.5
-
cpe:2.3:a:tipsandtricks-hq:all_in_one_wp_security_&_firewall:1.6
-
cpe:2.3:a:tipsandtricks-hq:all_in_one_wp_security_&_firewall:1.7
-
cpe:2.3:a:tipsandtricks-hq:all_in_one_wp_security_&_firewall:1.8
-
cpe:2.3:a:tipsandtricks-hq:all_in_one_wp_security_&_firewall:1.9
-
cpe:2.3:a:tipsandtricks-hq:all_in_one_wp_security_&_firewall:2.0
-
cpe:2.3:a:tipsandtricks-hq:all_in_one_wp_security_&_firewall:2.1
-
cpe:2.3:a:tipsandtricks-hq:all_in_one_wp_security_&_firewall:2.2
-
cpe:2.3:a:tipsandtricks-hq:all_in_one_wp_security_&_firewall:2.3
-
cpe:2.3:a:tipsandtricks-hq:all_in_one_wp_security_&_firewall:2.4
-
cpe:2.3:a:tipsandtricks-hq:all_in_one_wp_security_&_firewall:2.5
-
cpe:2.3:a:tipsandtricks-hq:all_in_one_wp_security_&_firewall:2.6
-
cpe:2.3:a:tipsandtricks-hq:all_in_one_wp_security_&_firewall:2.7
-
cpe:2.3:a:tipsandtricks-hq:all_in_one_wp_security_&_firewall:2.8
-
cpe:2.3:a:tipsandtricks-hq:all_in_one_wp_security_&_firewall:2.8.1
-
cpe:2.3:a:tipsandtricks-hq:all_in_one_wp_security_&_firewall:2.9
-
cpe:2.3:a:tipsandtricks-hq:all_in_one_wp_security_&_firewall:3.0
-
cpe:2.3:a:tipsandtricks-hq:all_in_one_wp_security_&_firewall:3.1
-
cpe:2.3:a:tipsandtricks-hq:all_in_one_wp_security_&_firewall:3.2
-
cpe:2.3:a:tipsandtricks-hq:all_in_one_wp_security_&_firewall:3.3
-
cpe:2.3:a:tipsandtricks-hq:all_in_one_wp_security_&_firewall:3.4
-
cpe:2.3:a:tipsandtricks-hq:all_in_one_wp_security_&_firewall:3.5
-
cpe:2.3:a:tipsandtricks-hq:all_in_one_wp_security_&_firewall:3.6
-
cpe:2.3:a:tipsandtricks-hq:all_in_one_wp_security_&_firewall:3.7
-
cpe:2.3:a:tipsandtricks-hq:all_in_one_wp_security_&_firewall:3.7.1
-
cpe:2.3:a:tipsandtricks-hq:all_in_one_wp_security_&_firewall:3.7.2
-
cpe:2.3:a:tipsandtricks-hq:all_in_one_wp_security_&_firewall:3.7.3
-
cpe:2.3:a:tipsandtricks-hq:all_in_one_wp_security_&_firewall:3.7.4
-
cpe:2.3:a:tipsandtricks-hq:all_in_one_wp_security_&_firewall:3.7.5
-
cpe:2.3:a:tipsandtricks-hq:all_in_one_wp_security_&_firewall:3.7.6
-
cpe:2.3:a:tipsandtricks-hq:all_in_one_wp_security_&_firewall:3.7.7
-
cpe:2.3:a:tipsandtricks-hq:all_in_one_wp_security_&_firewall:3.7.8
-
cpe:2.3:a:tipsandtricks-hq:all_in_one_wp_security_&_firewall:3.7.9
-
cpe:2.3:a:tipsandtricks-hq:all_in_one_wp_security_&_firewall:3.7.9.1
-
cpe:2.3:a:tipsandtricks-hq:all_in_one_wp_security_&_firewall:3.7.9.2
-
cpe:2.3:a:tipsandtricks-hq:all_in_one_wp_security_&_firewall:3.8.0
-
cpe:2.3:a:tipsandtricks-hq:all_in_one_wp_security_&_firewall:3.8.1
-
cpe:2.3:a:tipsandtricks-hq:all_in_one_wp_security_&_firewall:3.8.2
-
cpe:2.3:a:tipsandtricks-hq:all_in_one_wp_security_&_firewall:3.8.3
-
cpe:2.3:a:tipsandtricks-hq:all_in_one_wp_security_&_firewall:3.8.4
-
cpe:2.3:a:tipsandtricks-hq:all_in_one_wp_security_&_firewall:3.8.5
-
cpe:2.3:a:tipsandtricks-hq:all_in_one_wp_security_&_firewall:3.8.6
-
cpe:2.3:a:tipsandtricks-hq:all_in_one_wp_security_&_firewall:3.8.7
-
cpe:2.3:a:tipsandtricks-hq:all_in_one_wp_security_&_firewall:3.8.8
-
cpe:2.3:a:tipsandtricks-hq:all_in_one_wp_security_&_firewall:3.8.9
-
cpe:2.3:a:tipsandtricks-hq:all_in_one_wp_security_&_firewall:3.9.0
-
cpe:2.3:a:tipsandtricks-hq:all_in_one_wp_security_&_firewall:3.9.1
-
cpe:2.3:a:tipsandtricks-hq:all_in_one_wp_security_&_firewall:3.9.2
-
cpe:2.3:a:tipsandtricks-hq:all_in_one_wp_security_&_firewall:3.9.3
-
cpe:2.3:a:tipsandtricks-hq:all_in_one_wp_security_&_firewall:3.9.4
-
cpe:2.3:a:tipsandtricks-hq:all_in_one_wp_security_&_firewall:3.9.5
-
cpe:2.3:a:tipsandtricks-hq:all_in_one_wp_security_&_firewall:3.9.6
-
cpe:2.3:a:tipsandtricks-hq:all_in_one_wp_security_&_firewall:3.9.7
-
cpe:2.3:a:tipsandtricks-hq:all_in_one_wp_security_&_firewall:3.9.8
-
cpe:2.3:a:tipsandtricks-hq:all_in_one_wp_security_&_firewall:3.9.9
-
cpe:2.3:a:tipsandtricks-hq:all_in_one_wp_security_&_firewall:4.0.0
-
cpe:2.3:a:tipsandtricks-hq:all_in_one_wp_security_&_firewall:4.0.1
-
cpe:2.3:a:tipsandtricks-hq:all_in_one_wp_security_&_firewall:4.0.2
-
cpe:2.3:a:tipsandtricks-hq:all_in_one_wp_security_&_firewall:4.0.3
-
cpe:2.3:a:tipsandtricks-hq:all_in_one_wp_security_&_firewall:4.0.4
-
cpe:2.3:a:tipsandtricks-hq:all_in_one_wp_security_&_firewall:4.0.5
-
cpe:2.3:a:tipsandtricks-hq:all_in_one_wp_security_&_firewall:4.0.6
-
cpe:2.3:a:tipsandtricks-hq:all_in_one_wp_security_&_firewall:4.0.7
-
cpe:2.3:a:tipsandtricks-hq:all_in_one_wp_security_&_firewall:4.0.8
-
cpe:2.3:a:tipsandtricks-hq:all_in_one_wp_security_&_firewall:4.0.9
-
cpe:2.3:a:tipsandtricks-hq:all_in_one_wp_security_&_firewall:4.1.0
-
cpe:2.3:a:tipsandtricks-hq:all_in_one_wp_security_&_firewall:4.1.1
-
cpe:2.3:a:tipsandtricks-hq:all_in_one_wp_security_&_firewall:4.1.2
-
cpe:2.3:a:tipsandtricks-hq:all_in_one_wp_security_&_firewall:4.1.3
-
cpe:2.3:a:tipsandtricks-hq:all_in_one_wp_security_&_firewall:4.1.4
-
cpe:2.3:a:tipsandtricks-hq:all_in_one_wp_security_&_firewall:4.1.5
-
cpe:2.3:a:tipsandtricks-hq:all_in_one_wp_security_&_firewall:4.1.6
-
cpe:2.3:a:tipsandtricks-hq:all_in_one_wp_security_&_firewall:4.1.7
-
cpe:2.3:a:tipsandtricks-hq:all_in_one_wp_security_&_firewall:4.1.8
-
cpe:2.3:a:tipsandtricks-hq:all_in_one_wp_security_&_firewall:4.1.9
-
cpe:2.3:a:tipsandtricks-hq:all_in_one_wp_security_&_firewall:4.2.0