HomeDefault status
affected
Any version
affected
Description
The Payment Gateway for Telcell WordPress plugin through 2.0.1 does not validate the api_url parameter before redirecting the user to its value, leading to an Open Redirect issue
Problem types
CWE-601 URL Redirection to Untrusted Site ('Open Redirect')
Product status
Any version
Credits
Enrico Marcolini
Claudio Marchesini
WPScan
References
wpscan.com/...rability/f3e64947-3138-4ec4-86c4-27b5d6a5c9c2/