Description
WordPress Plugin GdeSlon Affiliate Shop is prone to an open redirect vulnerability because the application fails to properly sanitize user-supplied input. Exploiting this issue may allow attackers to redirect users to arbitrary web sites and conduct phishing attacks; other attacks are also possible. WordPress Plugin GdeSlon Affiliate Shop version 2.0 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.1 or latest
References
Related Vulnerabilities
WordPress Plugin Anti-Malware Security and Brute-Force Firewall Cross-Site Scripting (4.15.49)
WordPress Plugin Travelpayouts:All Travel Brands in One Place Cross-Site Scripting (0.7.12)
WordPress Plugin Ultimate Reviews PHP Object Injection (2.1.32)
WordPress Plugin MobileChief-Mobile Site Builder Cross-Site Scripting (1.5.7)