Login and Logout Redirect [login-and-logout-redirect] <= 2.0.3 (unfixed + closed)
unknown
[en] URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Swapnil V. Patil Login and Logout Redirect.This issue affects Login and Logout Redirect: from n/a through 2.0.3.
- Affected:
- up to 2.0.3
- Fix:
- No patched version reported
- Disclosed:
- Dec 19, 2023
CVE-2023-41648 on NVD →
Login and Logout Redirect <= 2.0.2 - Open Redirect
medium
The Login and Logout Redirect plugin for WordPress is vulnerable to Open Redirect in versions up to, and including, 2.0.2. This is due to insufficient validation on the redirect url supplied via the 'redirect_to' parameter. This makes it possible for unauthenticated attackers to redirect users to potentially malicious...
- CVSS:
- 6.1
- Affected:
- up to 2.0.2
- Fix:
- No patched version reported
- Disclosed:
- Sep 1, 2023
CVE-2023-41648 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database