Описание
The Auto-hyperlink URLs WordPress plugin through 5.4.1 does not set rel="noopener noreferer" on generated links, which can lead to Tab Nabbing by giving the target site access to the source tab through the window.opener DOM object.
Ссылки
- ExploitThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 5.4.1 (включая)
cpe:2.3:a:auto-hyperlink_urls_project:auto-hyperlink_urls:*:*:*:*:*:wordpress:*:*
EPSS
Процентиль: 41%
0.00188
Низкий
5.4 Medium
CVSS3
Дефекты
CWE-1022
NVD-CWE-Other
Связанные уязвимости
CVSS3: 5.4
github
больше 3 лет назад
The Auto-hyperlink URLs WordPress plugin through 5.4.1 does not set rel="noopener noreferer" on generated links, which can lead to Tab Nabbing by giving the target site access to the source tab through the window.opener DOM object.
EPSS
Процентиль: 41%
0.00188
Низкий
5.4 Medium
CVSS3
Дефекты
CWE-1022
NVD-CWE-Other