The WP Customer Reviews WordPress plugin before 3.7.1 does not validate a parameter allowing contributor and above users to redirect a page to a malicious URL
References
Link | Resource |
---|---|
https://wpscan.com/vulnerability/e6d9fe28-def6-4f25-9967-a77f91899bfe/ | Exploit Third Party Advisory |
https://wpscan.com/vulnerability/e6d9fe28-def6-4f25-9967-a77f91899bfe/ | Exploit Third Party Advisory |
Configurations
History
08 May 2025, 19:50
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:gowebsolutions:wp_customer_reviews:*:*:*:*:*:wordpress:*:* | |
CWE | NVD-CWE-noinfo | |
References | () https://wpscan.com/vulnerability/e6d9fe28-def6-4f25-9967-a77f91899bfe/ - Exploit, Third Party Advisory | |
First Time |
Gowebsolutions
Gowebsolutions wp Customer Reviews |
21 Nov 2024, 08:51
Type | Values Removed | Values Added |
---|---|---|
References | () https://wpscan.com/vulnerability/e6d9fe28-def6-4f25-9967-a77f91899bfe/ - |
03 Jul 2024, 01:45
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.4 |
15 Apr 2024, 13:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-04-15 05:15
Updated : 2025-05-08 19:50
NVD link : CVE-2024-1849
Mitre link : CVE-2024-1849
CVE.ORG link : CVE-2024-1849
JSON object : View
Products Affected
gowebsolutions
- wp_customer_reviews
CWE