The Protect WP Admin WordPress plugin before 4.0 discloses the URL of the admin panel via a redirection of a crafted URL, bypassing the protection offered.
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.
Link | Tags |
---|---|
https://wpscan.com/vulnerability/f8a29aee-19cd-4e62-b829-afc9107f69bd | patch third party advisory vdb entry exploit technical description |
https://magos-securitas.com/txt/CVE-2023-3139.txt | third party advisory |