CVE Database /
CVE-2021-24838
CVE · Medium
CVE-2021-24838 — AnyComment [anycomment] < 0.3.5
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2021-24838
|
AnyComment [anycomment] < 0.3.5 |
URL Redirection to Untrusted Site ('Open Redirect') |
Medium
6.1
|
< 0.3.5
|
0.3.5 |
2021-12-20 |
—
|
CVE-2021-24838
The AnyComment plugin through version 0.3.4 contains an open redirect vulnerability in an API endpoint that accepts a redirect parameter. User-supplied input passed to this parameter is sent directly to the wp_redirect() function without proper validation, allowing unauthenticated users to craft malicious redirect URLs that appear to originate from the affected site. The vulnerability was resolved in version 0.3.5.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings