The External Links in New Window / New Tab WordPress plugin before 1.43 does not ensure window.opener is set to "null" when links to external sites are clicked, which may enable tabnabbing attacks to occur.
                
            References
                    | Link | Resource | 
|---|---|
| https://wpscan.com/vulnerability/aa9d727c-4d17-4220-b8cb-e6dec30361a9 | Exploit Third Party Advisory | 
| https://wpscan.com/vulnerability/aa9d727c-4d17-4220-b8cb-e6dec30361a9 | Exploit Third Party Advisory | 
Configurations
                    Configuration 1 (hide)
| 
 | 
History
                    21 Nov 2024, 06:41
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () https://wpscan.com/vulnerability/aa9d727c-4d17-4220-b8cb-e6dec30361a9 - Exploit, Third Party Advisory | 
Information
                Published : 2022-05-30 09:15
Updated : 2024-11-21 06:41
NVD link : CVE-2022-1583
Mitre link : CVE-2022-1583
CVE.ORG link : CVE-2022-1583
JSON object : View
Products Affected
                webfactoryltd
- external_links_in_new_window_\/_new_tab
CWE
                
                    
                        
                        CWE-1022
                        
            Use of Web Link to Untrusted Target with window.opener Access
