Description
WordPress Plugin Wise Chat is prone to an open redirect vulnerability because the application fails to properly verify user-supplied input. Exploiting this issue may allow attackers to redirect users to arbitrary web sites and conduct phishing attacks; other attacks are also possible. WordPress Plugin Wise Chat version 2.6.3 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.7 or latest
References
https://www.exploit-db.com/exploits/46247
https://packetstormsecurity.com/files/151334/WordPress-Wisechat-2.6.3-Forced-Redirect-Phishing.html
https://plugins.svn.wordpress.org/wise-chat/trunk/readme.txt
Related Vulnerabilities
Internet Information Services Other Vulnerability (CVE-2000-0457)
WordPress Plugin WooCommerce Potential PHP Object Injection (3.4.4)
WordPress Plugin WP eCommerce Multiple Vulnerabilities (3.9.1)
Chamilo Improper Handling of Case Sensitivity Vulnerability (CVE-2023-3545)
Drupal Core 4.6.x Cross-Site Request Forgery (4.6.0 - 4.6.9)