CVE Vulnerabilities

CVE-2016-5832

Published: Jun 29, 2016 | Modified: Apr 12, 2025
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The customizer in WordPress before 4.5.3 allows remote attackers to bypass intended redirection restrictions via unspecified vectors.

Affected Software

NameVendorStart VersionEnd Version
WordpressWordpress*4.5.2 (including)
WordpressUbuntuartful*
WordpressUbuntuesm-apps/xenial*
WordpressUbuntuprecise*
WordpressUbuntutrusty*
WordpressUbuntuupstream*
WordpressUbuntuwily*
WordpressUbuntuxenial*
WordpressUbuntuyakkety*
WordpressUbuntuzesty*

References