External Links in New Window / New Tab [open-external-links-in-a-new-window] < 1.43
unknown
[en] The External Links in New Window / New Tab WordPress plugin before 1.43 does not ensure window.opener is set to "null" when links to external sites are clicked, which may enable tabnabbing attacks to occur.
- Affected:
- up to 1.43
- Fixed in:
- 1.43
- Disclosed:
- May 30, 2022
CVE-2022-1583 on NVD →
External Links in New Window / New Tab [open-external-links-in-a-new-window] < 1.43
unknown
[en] The External Links in New Window / New Tab WordPress plugin before 1.43 does not properly escape URLs it concatenates to onclick event handlers, which makes Stored Cross-Site Scripting attacks possible.
- Affected:
- up to 1.43
- Fixed in:
- 1.43
- Disclosed:
- May 30, 2022
CVE-2022-1582 on NVD →
External Links in New Window / New Tab <= 1.42 - Tabnabbing
medium
The External Links in New Window / New Tab WordPress plugin before 1.43 does not ensure window.opener is set to "null" when links to external sites are clicked, which may enable tabnabbing attacks to occur.
- CVSS:
- 6.5
- Affected:
- up to 1.42
- Fixed in:
- 1.43
- Disclosed:
- May 9, 2022
CVE-2022-1583 on NVD →
External Links in New Window / New Tab <= 1.42 - Unauthenticated Stored Cross-Site Scripting
medium
The External Links in New Window / New Tab WordPress plugin before 1.43 does not properly escape URLs it concatenates to onclick event handlers, which makes Stored Cross-Site Scripting attacks possible.
- CVSS:
- 6.1
- Affected:
- up to 1.42
- Fixed in:
- 1.43
- Disclosed:
- May 9, 2022
CVE-2022-1582 on NVD →
External Links in New Window / New Tab [open-external-links-in-a-new-window] < 1.43
unknown
Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability discovered by WPScanTeam in WordPress External Links in New Window / New Tab plugin (versions <= 1.42).
Update the WordPress External Links in New Window / New Tab plugin to the latest available version (at least 1.43).
- Affected:
- up to 1.43
- Fixed in:
- 1.43
- Disclosed:
- May 9, 2022
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database