The Payment Gateway for Telcell WordPress plugin through 2.0.1 does not validate the api_url parameter before redirecting the user to its value, leading to an Open Redirect issue
Advisories
Source ID Title
EUVD EUVD EUVD-2023-58998 The Payment Gateway for Telcell WordPress plugin through 2.0.1 does not validate the api_url parameter before redirecting the user to its value, leading to an Open Redirect issue
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 01 Aug 2025 02:00:00 +0000

Type Values Removed Values Added
First Time appeared Hkdigit
Hkdigit payment Gateway For Telcell
CPEs cpe:2.3:a:hkdigitalagency:payment_gateway_for_telcell:*:*:*:*:*:wordpress:*:* cpe:2.3:a:hkdigit:payment_gateway_for_telcell:*:*:*:*:*:wordpress:*:*
Vendors & Products Hkdigitalagency
Hkdigitalagency payment Gateway For Telcell
Hkdigit
Hkdigit payment Gateway For Telcell

Wed, 11 Jun 2025 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Hkdigitalagency
Hkdigitalagency payment Gateway For Telcell
Weaknesses CWE-601
CPEs cpe:2.3:a:hkdigitalagency:payment_gateway_for_telcell:*:*:*:*:*:wordpress:*:*
Vendors & Products Hkdigitalagency
Hkdigitalagency payment Gateway For Telcell

Sat, 17 May 2025 03:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 15 May 2025 20:15:00 +0000

Type Values Removed Values Added
Description The Payment Gateway for Telcell WordPress plugin through 2.0.1 does not validate the api_url parameter before redirecting the user to its value, leading to an Open Redirect issue
Title Payment Gateway for Telcell <= 2.0.1 - Unauthenticated Open Redirect
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2025-05-17T02:51:30.687Z

Reserved: 2023-12-13T16:08:13.067Z

Link: CVE-2023-6786

cve-icon Vulnrichment

Updated: 2025-05-17T02:51:24.359Z

cve-icon NVD

Status : Analyzed

Published: 2025-05-15T20:15:29.520

Modified: 2025-08-01T01:56:50.953

Link: CVE-2023-6786

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.