CVE-2024-0337
20.03.2024, 05:15
The Travelpayouts: All Travel Brands in One Place WordPress plugin through 1.1.15 is vulnerable to Open Redirect due to insufficient validation on the travelpayouts_redirect variable. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they can successfully trick them into performing an action.
Vendor | Product | Version |
---|---|---|
travelpayouts | travelpayouts | 𝑥 < 1.1.17 |
travelpayouts | travelpayouts | 𝑥 < 1.1.17 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration