Description
WordPress Plugin Wise Chat is prone to an open redirect vulnerability because the application fails to properly verify user-supplied input. Exploiting this issue may allow attackers to redirect users to arbitrary web sites and conduct phishing attacks; other attacks are also possible. WordPress Plugin Wise Chat version 2.6.3 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.7 or latest
References
https://www.exploit-db.com/exploits/46247
https://packetstormsecurity.com/files/151334/WordPress-Wisechat-2.6.3-Forced-Redirect-Phishing.html
https://plugins.svn.wordpress.org/wise-chat/trunk/readme.txt
Related Vulnerabilities
WordPress Plugin Gwolle Guestbook Multiple Vulnerabilities (2.1.0)
WordPress Plugin Facebook Like Box Cross-Site Request Forgery (2.8.2)
WordPress Plugin Custom Contact Forms Multiple Cross-Site Scripting Vulnerabilities (5.0.0.1)
WordPress Plugin P3 (Plugin Performance Profiler) Cross-Site Scripting (1.5.3.8)