Description
WordPress Plugin Under Construction is prone to an open redirect vulnerability because the application fails to properly verify user-supplied input. Exploiting this issue may allow attackers to redirect users to arbitrary web sites and conduct phishing attacks; other attacks are also possible. WordPress Plugin Under Construction version 3.20 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 3.25 or latest
References
Related Vulnerabilities
WordPress Plugin Calendar Event Multi View Unspecified Vulnerability (1.3.58)
WordPress Plugin FV Flowplayer Video Player URL Cross-Site Scripting (1.2.11)
Oracle JRE CVE-2013-5775 Vulnerability (CVE-2013-5775)
WebLogic CVE-2010-2375 Vulnerability (CVE-2010-2375)
ownCloud Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-1500)