CVE-2023-6786
MEDIUM NUCLEIHkdigit Payment Gateway For Telcell < 2.0.4 - Open Redirect
Title source: ruleDescription
The Payment Gateway for Telcell WordPress plugin through 2.0.1 does not validate the api_url parameter before redirecting the user to its value, leading to an Open Redirect issue
Exploits (1)
github
WORKING POC
4 stars
by halilkirazkaya · poc
https://github.com/halilkirazkaya/cve-poc-garage/tree/main/2023/CVE-2023-6786.md
Nuclei Templates (1)
Payment Gateway for Telcell < 2.0.4 - Open Redirect
MEDIUMVERIFIEDby s4e-io
Scores
CVSS v3
6.1
EPSS
0.0099
EPSS Percentile
76.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Classification
CWE
CWE-601
Status
published
Affected Products (1)
hkdigit/payment_gateway_for_telcell
< 2.0.4
Timeline
Published
May 15, 2025
Tracked Since
Feb 18, 2026