The Travelpayouts: All Travel Brands in One Place WordPress plugin through 1.1.15 is vulnerable to Open Redirect due to insufficient validation on the travelpayouts_redirect variable. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they can successfully trick them into performing an action.
History

Mon, 05 May 2025 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Travelpayouts
Travelpayouts travelpayouts
Weaknesses CWE-601
CPEs cpe:2.3:a:travelpayouts:travelpayouts:*:*:*:*:*:wordpress:*:*
Vendors & Products Travelpayouts
Travelpayouts travelpayouts

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2024-03-20T05:00:02.494Z

Updated: 2024-08-01T18:18:19.215Z

Reserved: 2024-01-09T11:34:03.278Z

Link: CVE-2024-0337

cve-icon Vulnrichment

Updated: 2024-08-01T18:04:49.610Z

cve-icon NVD

Status : Analyzed

Published: 2024-03-20T05:15:45.387

Modified: 2025-05-05T18:48:54.833

Link: CVE-2024-0337

cve-icon Redhat

No data.