WordPress Plugin Vulnerabilities
Google Adsense & Hotel Booking <= 1.0.5 - Open Proxy
Description
Plugin is still affected and has been closed.
The code in ./plugin/google-adsense-and-hotel-booking/proxy.php allows an arbitrary user to proxy POST requests though the host site.
This may allow attackers to hide attacks, or DoS a site if the POST request is pointed back at itself causing a loop.
Proof of Concept
Affects Plugins
References
CVE
Classification
Type
REDIRECT
OWASP top 10
CWE
CVSS
Miscellaneous
Submitter
Larry W. Cashdollar
Submitter twitter
Verified
No
WPVDB ID
Timeline
Publicly Published
2015-08-15 (about 10 years ago)
Added
2015-08-24 (about 10 years ago)
Last Updated
2020-09-22 (about 5 years ago)