Travelpayouts <= 1.1.15 - Open Redirect
Published Mar 20, 2024
6.1
MEDIUMCVSS 3.1
EPSS 0.89%
Description
The Travelpayouts: All Travel Brands in One Place WordPress plugin through 1.1.15 is vulnerable to Open Redirect due to insufficient validation on the travelpayouts_redirect variable. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they can successfully trick them into performing an action.
Affected products
- Vendor n/a Product Travelpayouts: All Travel Brands in One Place Defaultaffected
- Version 0StatusaffectedConstraints<=1.1.15
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Travelpayouts: All Travel Brands in One Place | affected |
|
- < 1.1.17
-
- Version 0StatusaffectedConstraints<1.1.17
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Travelpayouts | Travelpayouts | affected |
|
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (1)
- https://wpscan.com/vulnerability/2f17a274-8676-4f4e-989f-436030527890/ exploitvdb-entrytechnical-descriptionThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://wpscan.com/vulnerability/2f17a274-8676-4f4e-989f-436030527890/ | exploitvdb-entrytechnical-descriptionThird Party Advisory |
Change history (0)
No recorded changes yet.