WPSID Shortcode <= 1.0.9.2 - Open Redirect
mediumThe WPSID Shortcode plugin for WordPress is vulnerable to Open Redirect due to the plugin accepting a user-supplied redirect location via the 'wpsid-redirect-to' parameter in versions up to, and including, 1.0.9.2.
- CVSS:
- 6.1
- Affected:
- up to 1.0.9.2
- Fix:
- No patched version reported
- Disclosed:
- May 31, 2022