CVE-2024-1849

Publication date

2024-04-15 05:00:05

Family

WPScan

State

PUBLISHED

Description

The WP Customer Reviews WordPress plugin before 3.7.1 does not validate a parameter allowing contributor and above users to redirect a page to a malicious URL