Description
WordPress Plugin Wise Chat is prone to an open redirect vulnerability because the application fails to properly verify user-supplied input. Exploiting this issue may allow attackers to redirect users to arbitrary web sites and conduct phishing attacks; other attacks are also possible. WordPress Plugin Wise Chat version 2.6.3 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.7 or latest
References
https://www.exploit-db.com/exploits/46247
https://packetstormsecurity.com/files/151334/WordPress-Wisechat-2.6.3-Forced-Redirect-Phishing.html
https://plugins.svn.wordpress.org/wise-chat/trunk/readme.txt
Related Vulnerabilities
MediaWiki Credentials Management Errors Vulnerability (CVE-2015-8009)
WordPress Plugin WP Discourse Unspecified Vulnerability (0.9.7)
WordPress Plugin Booking Package-Appointment Booking Calendar System Cross-Site Scripting (1.5.10)
MySQL CVE-2016-3495 Vulnerability (CVE-2016-3495)
Oracle Database Server Permissions, Privileges, and Access Controls Vulnerability (CVE-2008-6065)