nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2019-6780 CVE-2019-6780
MEDIUM
WordPress Plugin Wisechat 2.6.3 - Reverse Tabnabbing
Record summary
CVE-2019-6780 has a selected CVSS score of 6.1 (medium); EIP currently links 1 catalogued exploit.
Description
The Wise Chat plugin before 2.7 for WordPress mishandles external links because rendering/filters/post/WiseChatLinksPostFilter.php omits noopener and noreferrer.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBWordPress Plugin Wisechat 2.6.3 - Reverse TabnabbingExploitDB exploitby MTKNot analyzed1 file
References
4plugins.trac.wordpress.org
https://plugins.trac.wordpress.org/changeset/2016929/wise-chat/trunk/src/rendering/filters/post/WiseChatLinksPostFilter.php wordpress.org
https://wordpress.org/plugins/wise-chat 46247exploit
https://www.exploit-db.com/exploits/46247