The wccp-pro WordPress plugin before 15.3 contains an open-redirect flaw via the referrer parameter, allowing redirection of users to external sites
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.
Link | Tags |
---|---|
https://wpscan.com/vulnerability/09c6848d-30dc-4382-ae74-b470f586e142/ | third party advisory exploit technical description vdb entry |