The plugin does not validate the tribe_tickets_redirect_to parameter before redirecting the user to the given value, leading to an arbitrary redirect issue
https://exampel.com/wp-admin/admin.php?page=wp_ajax_rsvp-form&tribe_tickets_redirect_to=https://wpscan.com
Krzysztof Zając
Krzysztof Zając
Yes
2021-12-22 (about 1 years ago)
2021-12-22 (about 1 years ago)
2022-04-13 (about 9 months ago)