CVE-2025-30859
CVSS 3.1 Score 4.7 of 10 (medium)
Details
Summary
CVE-2025-30859 is a new Open Redirect vulnerability affecting AliNext, a popular e-commerce plugin for Magento. Hackers can exploit this issue by manipulating URLs, redirecting unsuspecting users to fraudulent or malicious websites. This allows attackers to carry out phishing attacks and gain unauthorized access to sensitive user information. AliNext versions from n/a through 3.5.1 are impacted by this vulnerability. It is crucial that users of these affected versions take immediate action to apply the latest patches or upgrades to secure their websites against these attacks.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- WordPress