CVE-2025-39417
CVSS 3.1 Score 7.1 of 10 (high)
Details
Summary
CVE-2025-39417 is a Cross-Site Request Forgery (CSRF) vulnerability affecting the Redirect wordpress to welcome or landing page plugin. An attacker can exploit this issue to perform Stored XSS (Cross-Site Scripting) attacks on unsuspecting users. The vulnerability allows an attacker to inject malicious scripts into the webpage visited by the user after they have been redirected. This issue affects all versions of the plugin from the earliest release through 2.0. Users are advised to update to the latest version of the plugin or consider disabling the plugin as a temporary measure until a patch is available.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.