← Back to CVE List

CVE-2021-24838

Published: 2022-01-17T13:15Z
Last Modified: 2024-11-21T05:53Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
The AnyComment WordPress plugin before 0.3.5 has an API endpoint which passes user input via the redirect parameter to the wp_redirect() function without being validated first, leading to an Open Redirect issue, which according to the vendor, is a feature. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt