In affected versions of WordPress, due to an issue in wp_validate_redirect() and URL sanitization, an arbitrary external link can be crafted leading to unintended/open redirect when clicked. This has been patched in version 5.4.2, along with all the previously affected versions via a minor release (5.3.4, 5.2.7, 5.1.6, 5.0.10, 4.9.15, 4.8.14, 4.7.18, 4.6.19, 4.5.22, 4.4.23, 4.3.24, 4.2.28, 4.1.31, 4.0.31, 3.9.32, 3.8.34, 3.7.34).
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2024-08-04T07:52:20.833Z

Reserved: 2019-12-30T00:00:00

Link: CVE-2020-4048

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-06-12T16:15:10.623

Modified: 2024-11-21T05:32:13.273

Link: CVE-2020-4048

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.