Bridge Theme <= 18.2, Qode Instagram Widget <=2.0.1, Qode Twitter Feed <= 2.0.0 - Open Redirect
Affected versions: [*, 18.2.1); [*, 2.0.2); [*, 2.0.1)
Vulnerability type: CWE-601 URL Redirection to Untrusted Site ('Open Redirect')
Affected software, patched versions and attribution
Helper plugins packaged with Bridge theme possess an Open Redirect vulnerability, allowing a malicious actor to create links to the site that redirect people to malicious domains. The Bridge theme, Qode Instagram Widget plugin, and Qode Twitter Feed plugin for WordPress are vulnerable to open redirects via the url parameter due to missing validation on the redirect location, that makes it possible for attackers to redirect unsuspecting users to malicious sites. This affects versions up to 18.2.1 in the Bridge theme, versions up to 2.0.2 in the Instagram widget plugin, and versions up to 2.0.1 in the Twitter feed plugin, and can be exploited by unauthenticated users.
Bridge - Creative Multipurpose WordPress Theme
Affected versions: [*, 18.2.1)
Patched versions: 18.2.1
Bridge Theme Qode Instagram Widget
Affected versions: [*, 2.0.2)
Patched versions: 2.0.2
Bridge Theme Qode Twitter Feed
Affected versions: [*, 2.0.1)
Patched versions: 2.0.1
Researcher credit: Mikey Veenstra
Applicable copyright and licence notices
This record contains material that is subject to copyright
Copyright 2012-2026 Defiant Inc.
Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.
- Published
- October 21, 2019
- CVSS
- 7.1