The URL Shortify WordPress plugin before 1.7.6 does not properly escape the value of the referer header, thus allowing an unauthenticated attacker to inject malicious javascript that will trigger in the plugins admin panel with statistics of the created short link.
Metrics
Affected Vendors & Products
References
History
Fri, 02 May 2025 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: WPScan
Published: 2023-09-11T19:46:09.500Z
Updated: 2025-05-02T17:40:10.398Z
Reserved: 2023-08-10T12:56:23.278Z
Link: CVE-2023-4294

Updated: 2024-08-02T07:24:04.243Z

Status : Modified
Published: 2023-09-11T20:15:11.973
Modified: 2025-05-02T18:15:25.730
Link: CVE-2023-4294

No data.