S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2015-5461 Scanner

CVE-2015-5461 scanner - Open Redirect vulnerability in StageShow plugin for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.7k
Times Used
continuous scan runs
3.9k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2015-5461
6.4
CVSS

Open redirect vulnerability in the Redirect function in stageshow_redirect.php in the StageShow plugin before 5.0.9 for WordPress allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the url parameter.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

The StageShow plugin for WordPress is a tool for creating and managing events and performances on a website. It offers features for managing ticket sales, seating arrangements, and promotional materials. The plugin is widely used and popular among event organizers and performance venues.

However, the StageShow plugin is not without its security vulnerabilities. One such vulnerability, CVE-2015-5461, allows attackers to exploit an open redirect vulnerability in the Redirect function of the plugin. This vulnerability can be triggered by a URL in the url parameter, allowing attackers to redirect users to arbitrary websites and conduct phishing attacks.

If exploited, the CVE-2015-5461 vulnerability can lead to serious consequences for both the website owner and its users. Attackers can use the vulnerability to steal sensitive information such as login credentials, credit card numbers, and other personal data. They can also use the vulnerability to launch further attacks on the website or its users.

Thanks to the pro features of the s4e.io platform, readers of this article can easily and quickly learn about vulnerabilities in their digital assets. The platform offers comprehensive scanning and testing tools, along with personalized reports and recommendations for improving website and network security. With s4e.io, website owners can stay one step ahead of potential attackers and protect their online assets.

 

REFERENCES

Solution Advice

To protect against this vulnerability, website owners should take the following precautions:

  • Ensure that the StageShow plugin is up to date with the latest security patches
  • Disable or restrict the use of the Redirect function in the plugin
  • Implement web application firewalls and intrusion detection systems to monitor for attempts to exploit the vulnerability
  • Perform regular security audits and vulnerability scans of the website

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2015-5461 scanner - Open Redirect vulnerability in StageShow plugin for WordPress | S4E