CVE-2024-0337

The Travelpayouts: All Travel Brands in One Place WordPress plugin through 1.1.15 is vulnerable to Open Redirect due to insufficient validation on the travelpayouts_redirect variable. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they can successfully trick them into performing an action.
CVSS

No CVSS.

Configurations

Configuration 1 (hide)

cpe:2.3:a:travelpayouts:travelpayouts:*:*:*:*:*:wordpress:*:*

History

05 May 2025, 18:48

Type Values Removed Values Added
CPE cpe:2.3:a:travelpayouts:travelpayouts:*:*:*:*:*:wordpress:*:*
First Time Travelpayouts travelpayouts
Travelpayouts
References () https://wpscan.com/vulnerability/2f17a274-8676-4f4e-989f-436030527890/ - () https://wpscan.com/vulnerability/2f17a274-8676-4f4e-989f-436030527890/ - Exploit, Third Party Advisory
CWE CWE-601

20 Mar 2024, 05:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-03-20 05:15

Updated : 2025-05-05 18:48


NVD link : CVE-2024-0337

Mitre link : CVE-2024-0337


JSON object : View

Products Affected

travelpayouts

  • travelpayouts
CWE
CWE-601

URL Redirection to Untrusted Site ('Open Redirect')