GdeSlon Affiliate Shop <= 1.5.5 - Open Redirect
mediumThe GdeSlon Affiliate Shop plugin for WordPress is vulnerable to Open Redirect in versions up to, and including, 1.5.5 via the go.php file. This makes it possible for unauthenticated attackers to redirect users with contributer-level permissions and above to a potentially malicious website where they can gather sensiti...
- CVSS:
- 6.1
- Affected:
- up to 1.5.5
- Fixed in:
- 2.0
- Disclosed:
- May 25, 2014