CVE-2024-3032 describes an Open Redirect vulnerability in the Themify Builder WordPress plugin versions prior to 7.5.8. This flaw allows an attacker to redirect users to arbitrary malicious websites due to improper validation of a redirection parameter. Rated as MEDIUM severity with a CVSS score of 6.1, the vulnerability can be exploited remotely with low attack complexity, requiring user interaction. A successful exploit could lead to information disclosure and potentially compromise user credentials through phishing. Currently, there is no evidence of active exploitation, and it is not listed on the CISA KEV catalog. While no Metasploit or ExploitDB modules exist, Nuclei templates are available, indicating potential for automated scanning and exploitation. Community discussion and media coverage are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 7.5.8CPE matchmatch criteria | cpe:2.3:a:themify:builder:*:*:*:*:-:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.