WordPress Core, the software used to create websites, is vulnerable to a security issue in versions up to 6.0.3. This means an attacker can redirect a victim to a malicious website if the victim clicks on a link. This happens because the software does not properly validate the ‘Referer’ header and certain request parameters when a user clicks a link with an expired or invalid nonce.