The Travelpayouts: All Travel Brands in One Place WordPress plugin through 1.1.15 is vulnerable to Open Redirect due to insufficient validation on the travelpayouts_redirect variable. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they can successfully trick them into performing an action.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 05 May 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Travelpayouts
Travelpayouts travelpayouts |
|
| Weaknesses | CWE-601 | |
| CPEs | cpe:2.3:a:travelpayouts:travelpayouts:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Travelpayouts
Travelpayouts travelpayouts |
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2024-08-01T18:18:19.215Z
Reserved: 2024-01-09T11:34:03.278Z
Link: CVE-2024-0337
Updated: 2024-08-01T18:04:49.610Z
Status : Analyzed
Published: 2024-03-20T05:15:45.387
Modified: 2025-05-05T18:48:54.833
Link: CVE-2024-0337
No data.
OpenCVE Enrichment
No data.
Weaknesses