WordPress versions prior to 3.6.1 do not check URLs carefully enough before using them to redirect to another website. This can be used by malicious attackers to redirect people away from the intended website without their permission.
Documentation: Home / Vulnerabilities / Input validation vulnerability in WordPress 3.6
WordPress versions prior to 3.6.1 do not check URLs carefully enough before using them to redirect to another website. This can be used by malicious attackers to redirect people away from the intended website without their permission.
This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!
Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:
> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21
Is this information incorrect? Please leave us a message.
© Really Simple Plugins
CoC 70461155
Kalmarweg 14-5
9723 JG, Groningen (NL)