WordPress versions before 4.8.2 contain an open redirect caused by improper validation in wp-admin/edit-tag-form.php and wp-admin/user-edit.php, letting attackers redirect users to malicious sites, exploit requires access to admin interface.
id: CVE-2017-14725
info:
name: WordPress < 4.8.2 - Authenticated Open Redirect
author: 0x_Akoko
...