Themify Builder WordPress plugin before 7.5.8 does not validate a parameter before redirecting the user to its value, leading to an Open Redirect issue
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.
Link | Tags |
---|---|
https://wpscan.com/vulnerability/d130a60c-c36b-4994-9b0e-e52cd7f99387/ | third party advisory vdb entry exploit technical description |