CVE-2024-13888 is an Open Redirect vulnerability affecting all versions up to and including 11.56 of the WPMobile.App plugin for WordPress. This flaw allows unauthenticated attackers to redirect users to malicious sites due to insufficient validation of the 'redirect' parameter. Rated Medium severity (CVSS 6.1), it requires user interaction for exploitation, potentially leading to information disclosure and integrity impacts. While no active exploitation or public exploit code (Metasploit, ExploitDB) is reported, Nuclei templates exist, and community discussion and media coverage are currently minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 11.57CPE matchmatch criteria | cpe:2.3:a:amauri:wpmobile.app:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.