WordPress English Admin plugin before 1.5.2 contains an open redirect vulnerability. The plugin does not validate the admin_custom_language_return_url before redirecting users to it. An attacker can possibly obtain sensitive information, modify data, and/or execute unauthorized operations.
id: CVE-2021-25111
info:
name: WordPress English Admin <1.5.2 - Open Redirect
author: akincibor
...