Description
The Travelpayouts: All Travel Brands in One Place WordPress plugin through 1.1.15 is vulnerable to Open Redirect due to insufficient validation on the travelpayouts_redirect variable. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they can successfully trick them into performing an action.
Published: 2024-03-20
Score: 6.1 Medium
EPSS: 1.2% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 May 2025 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Travelpayouts
Travelpayouts travelpayouts
Weaknesses CWE-601
CPEs cpe:2.3:a:travelpayouts:travelpayouts:*:*:*:*:*:wordpress:*:*
Vendors & Products Travelpayouts
Travelpayouts travelpayouts

Subscriptions

Travelpayouts Travelpayouts
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2024-08-01T18:18:19.215Z

Reserved: 2024-01-09T11:34:03.278Z

Link: CVE-2024-0337

cve-icon Vulnrichment

Updated: 2024-08-01T18:04:49.610Z

cve-icon NVD

Status : Analyzed

Published: 2024-03-20T05:15:45.387

Modified: 2025-05-05T18:48:54.833

Link: CVE-2024-0337

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses