### [CVE-2021-25028](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-25028) ![](https://img.shields.io/static/v1?label=Product&message=Event%20Tickets&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=5.2.2%3C%205.2.2%20&color=brighgreen) ![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-601%20URL%20Redirection%20to%20Untrusted%20Site%20('Open%20Redirect')&color=brighgreen) ### Description The Event Tickets WordPress plugin before 5.2.2 does not validate the tribe_tickets_redirect_to parameter before redirecting the user to the given value, leading to an arbitrary redirect issue ### POC #### Reference - https://wpscan.com/vulnerability/80b0682e-2c3b-441b-9628-6462368e5fc7 #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/ARPSyndicate/kenzer-templates