Description
WordPress before 3.6.1 does not properly validate URLs before use in an HTTP redirect, which allows remote attackers to bypass intended redirection restrictions via a crafted string.
Remediation
References
Related Vulnerabilities
MySQL CVE-2021-35602 Vulnerability (CVE-2021-35602)
Oracle Application Server CVE-2009-3412 Vulnerability (CVE-2009-3412)
Liferay Portal Incorrect Default Permissions Vulnerability (CVE-2022-42128)
MySQL CVE-2021-2076 Vulnerability (CVE-2021-2076)
Grafana Authorization Bypass Through User-Controlled Key Vulnerability (CVE-2024-10452)