Description
WordPress Plugin WooCommerce is prone to an open redirect vulnerability because the application fails to properly verify user-supplied input. Exploiting this issue may allow attackers to redirect users to arbitrary web sites and conduct phishing attacks; other attacks are also possible. WordPress Plugin WooCommerce version 3.7.0 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 3.7.1 or latest
References
Related Vulnerabilities
WordPress Plugin Minimal Coming Soon & Maintenance Mode-Coming Soon Page Open Redirect (1.85)
WordPress Plugin WP No External Links Cross-Site Scripting (3.5.15)
WordPress Plugin WordPress Download Manager Cross-Site Scripting (2.7.94)
WordPress Plugin Secure HTML5 Video Player Cross-Site Scripting (3.14)