Description
WordPress Plugin Wise Chat is prone to an open redirect vulnerability because the application fails to properly verify user-supplied input. Exploiting this issue may allow attackers to redirect users to arbitrary web sites and conduct phishing attacks; other attacks are also possible. WordPress Plugin Wise Chat version 2.6.3 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.7 or latest
References
https://www.exploit-db.com/exploits/46247
https://packetstormsecurity.com/files/151334/WordPress-Wisechat-2.6.3-Forced-Redirect-Phishing.html
https://plugins.svn.wordpress.org/wise-chat/trunk/readme.txt
Related Vulnerabilities
OpenSSL Other Vulnerability (CVE-2015-0207)
PrestaShop Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2013-4792)
Jenkins Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-2603)
Liferay Portal Insufficiently Protected Credentials Vulnerability (CVE-2021-29043)
Moodle Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2021-43559)