Description
The Meta Tag Manager WordPress plugin before 3.3 does not restrict which roles can create http-equiv refresh meta tags.
Problem types
CWE-601 URL Redirection to Untrusted Site ('Open Redirect')
Product status
Any version before 3.3
Credits
Pierre Rudloff
WPScan
References
wpscan.com/...rability/4a2d4dcf-bb34-4eec-b5de-31c6a4d823cf/