mirror of
https://github.com/0xMarcio/cve.git
synced 2025-06-19 17:30:12 +00:00
840 B
840 B
CVE-2024-1849
Description
The WP Customer Reviews WordPress plugin before 3.7.1 does not validate a parameter allowing contributor and above users to redirect a page to a malicious URL
POC
Reference
- https://wpscan.com/vulnerability/e6d9fe28-def6-4f25-9967-a77f91899bfe/
- https://wpscan.com/vulnerability/e6d9fe28-def6-4f25-9967-a77f91899bfe/