The Plus Addons for Elementor Page Builder WordPress plugin before 4.1.10 did not validate a redirect parameter on a specifically crafted URL before redirecting the user to it, leading to an Open Redirect issue.
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.
Link | Tags |
---|---|
https://theplusaddons.com/changelog/ | release notes vendor advisory |
https://wpscan.com/vulnerability/fd4352ad-dae0-4404-94d1-11083cb1f44d | third party advisory exploit |