Description
The Wp Edit Password Protected WordPress plugin before 1.3.5 does not validate a parameter before redirecting the user to its value, leading to an Open Redirect issue
Problem types
CWE-601 URL Redirection to Untrusted Site ('Open Redirect')
Product status
Any version before 1.3.5
Credits
Bob Matyas
WPScan
References
wpscan.com/...rability/3cf79a0b-2731-47f8-a397-995f4de7067e/