CVE · Medium

CVE-2021-24838 — AnyComment [anycomment] < 0.3.5

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2021-24838 AnyComment [anycomment] < 0.3.5 URL Redirection to Untrusted Site ('Open Redirect') Medium 6.1 < 0.3.5 0.3.5 2021-12-20

CVE-2021-24838

The AnyComment plugin through version 0.3.4 contains an open redirect vulnerability in an API endpoint that accepts a redirect parameter. User-supplied input passed to this parameter is sent directly to the wp_redirect() function without proper validation, allowing unauthenticated users to craft malicious redirect URLs that appear to originate from the affected site. The vulnerability was resolved in version 0.3.5.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.