plugin

Login And Logout Redirect Vulnerabilities

2 known security issues reported for the Login And Logout Redirect WordPress plugin. Most recent disclosed Dec 19, 2023.

1 medium

Running Login And Logout Redirect on your site? Check whether your installed version is affected.

Scan your site free

Login and Logout Redirect [login-and-logout-redirect] <= 2.0.3 (unfixed + closed)

unknown

[en] URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Swapnil V. Patil Login and Logout Redirect.This issue affects Login and Logout Redirect: from n/a through 2.0.3.

Affected:
up to 2.0.3
Fix:
No patched version reported
Disclosed:
Dec 19, 2023

CVE-2023-41648 on NVD →

Login and Logout Redirect <= 2.0.2 - Open Redirect

medium

The Login and Logout Redirect plugin for WordPress is vulnerable to Open Redirect in versions up to, and including, 2.0.2. This is due to insufficient validation on the redirect url supplied via the 'redirect_to' parameter. This makes it possible for unauthenticated attackers to redirect users to potentially malicious...

CVSS:
6.1
Affected:
up to 2.0.2
Fix:
No patched version reported
Disclosed:
Sep 1, 2023

CVE-2023-41648 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database