The AnyComment WordPress plugin before 0.3.5 has an API endpoint which passes user input via the redirect parameter to the wp_redirect() function without being validated first, leading to an Open Redirect issue, which according to the vendor, is a feature.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: WPScan
Published: 2022-01-17T13:00:27
Updated: 2024-08-03T19:42:17.311Z
Reserved: 2021-01-14T00:00:00
Link: CVE-2021-24838
Vulnrichment
No data.
NVD
Status : Modified
Published: 2022-01-17T13:15:07.577
Modified: 2024-11-21T05:53:51.797
Link: CVE-2021-24838
Redhat
No data.