There is an open redirect in the PhastPress WordPress plugin before 1.111 that allows an attacker to malform a request to a page with the…
WPScan·CWE-601·Published 2021-04-05
There is an open redirect in the PhastPress WordPress plugin before 1.111 that allows an attacker to malform a request to a page with the plugin and then redirect the victim to a malicious page. There is also a support comment from another user one year ago (https://wordpress.org/support/topic/phast-php-used-for-remote-fetch/) that says that the php involved in the request only go to whitelisted pages but it's possible to redirect the victim to any domain.
There is an open redirect in the PhastPress WordPress plugin before 1.111 that allows an attacker to malform a request to a page with the plugin and then redirect the victim to a malicious page. There is also a support comment from another user one year ago (https://wordpress.org/support/topic/phast-php-used-for-remote-fetch/) that says that the php involved in the request only go to whitelisted pages but it's possible to redirect the victim to any domain.
Se presenta un redireccionamiento abierto en el plugin PhastPress WordPress versiones anteriores a 1.111, que permite a un atacante malformar una petición hacia una página con el plugin y luego redireccionar a la víctima hacia una página maliciosa. También se presenta un comentario de soporte de otro usuario hace un año (https://wordpress.org/support/topic/phast-php-used-for-remote-fetch/) que dice que el php involucrado en la petición solo va a páginas incluidas en la lista blanca, pero es posible redireccionar a la víctima a cualquier dominio
| Version | Type | Source | Base | Exp | Impact | Vector |
|---|---|---|---|---|---|---|
| 2.0 | Primary | NVD | 5.8 | 8.6 | 4.9 | AV:N/AC:M/Au:N/C:P/I:P/A:N |
| 3.1 | Primary | NVD | 6.1 | 2.8 | 2.7 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |