Input validation vulnerability in WP Gravity Forms Zendesk 1.1.2

The WP Gravity Forms Zendesk plugin for WordPress has a vulnerability, up to version 1.1.2, where the redirect url for the ‘state’ parameter is not properly validated. This means that attackers who are not logged in can redirect users to dangerous websites by tricking them into clicking on something.

Detected in:

WP Gravity Forms Zendesk fixed vulnerable versions: >= * <= 1.1.2

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.