Description
WordPress Plugin GdeSlon Affiliate Shop is prone to an open redirect vulnerability because the application fails to properly sanitize user-supplied input. Exploiting this issue may allow attackers to redirect users to arbitrary web sites and conduct phishing attacks; other attacks are also possible. WordPress Plugin GdeSlon Affiliate Shop version 2.0 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.1 or latest
References
Related Vulnerabilities
WordPress Plugin YITH WooCommerce Compare Security Bypass (2.3.13)
TYPO3 Insufficient Session Expiration Vulnerability (CVE-2022-23502)
Internet Information Services Other Vulnerability (CVE-2002-0073)
phpBB Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2007-5173)
VMware directory traversal and privilege escalation vulnerabilities