The WP Customer Reviews WordPress plugin before 3.7.1 does not validate a parameter allowing contributor and above users to redirect a page to a malicious URL
References
| Link | Resource |
|---|---|
| https://wpscan.com/vulnerability/e6d9fe28-def6-4f25-9967-a77f91899bfe/ | Exploit Third Party Advisory |
| https://wpscan.com/vulnerability/e6d9fe28-def6-4f25-9967-a77f91899bfe/ | Exploit Third Party Advisory |
Configurations
History
No history.
Information
Published : 2024-04-15 05:15
Updated : 2025-05-08 19:50
NVD link : CVE-2024-1849
Mitre link : CVE-2024-1849
CVE.ORG link : CVE-2024-1849
JSON object : View
Products Affected
gowebsolutions
- wp_customer_reviews
CWE
