QID 150460
Date Published: 2022-01-31
QID 150460: WordPress AnyComment Plugin: Open Redirect Vulnerability (CVE-2021-24838)
AnyComment is a plugin for WordPress, it allows users to easily add their comments via social networks.
In affected versions of AnyCommnet WordPress plugin a Open redirect vulnerability exists due to unvalidated user input supplied to redirect parameter.
Affected Versions:
AnyComment WordPress plugin through 0.2.17
QID Detection Logic:
This QID sends a HTTP GET request to "wp-json/anycomment/v1/auth/wordpress" with redirect parameter and based on the response confirms if the target is vulnerable.
Successful exploitation could allow attackers to trick a user into visiting a specially crafted link which would redirect them to an arbitrary malicious external URL.
Solution
There is no patch available, for more information refer the AnyComment site.
Vendor References
CVEs related to QID 150460
Software Advisories
| Advisory ID | Software | Component | Link |
|---|