exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

WordPress WPtouch Pro 3.0.9.1 Open Redirection

WordPress WPtouch Pro 3.0.9.1 Open Redirection
Posted Jan 18, 2023
Authored by indoushka

WordPress WPtouch Pro plugin version 3.0.9.1 suffers from an open redirection vulnerability.

tags | exploit
SHA-256 | aa646e4c74af216ce59dec0d567234b3847f7fef7d38d5aa13f98518c5851f75

WordPress WPtouch Pro 3.0.9.1 Open Redirection

Change Mirror Download
====================================================================================================================================
| # Title : WordPress -WPtouch Pro 3.0.9.1 Open Redirect Vulnerability |
| # Author : indoushka |
| # Tested on : windows 10 Français V.(Pro) / browser : Mozilla firefox 66.0(64-bit) |
| # Vendor : https://wordpress.org/plugins/wptouch/ |
| # Dork : wp-content/plugins/wptouch/ |
====================================================================================================================================

P0C :

== Description ==

WPtouch is a mobile plugin for WordPress that automatically adds a simple and elegant mobile theme for mobile visitors to your WordPress website.
When you activate the plugin and set it up, it allows the site visitor to view it according to the device used for browsing
However, when connected to a mobile device, Plugins allows you to switch the display between a desktop or a mobile device
Desktop browsing does not allow you to convert
But if we use the payload then it is possible.

This URL Redirection vulnerability allows remote
Attackers to redirect users to arbitrary websites and conduct phishing attacks

[+] Dorking İn Google Or Other Search Enggine.

[+] Use payload : /?wptouch_switch=desktop&redirect=https://packetstormsecurity.com

[+] https://127.0.0.1/arabslabcom/?wptouch_switch=desktop&redirect=https://packetstormsecurity.com


Greetings to :=========================================================================================================================
jericho * Larry W. Cashdollar * brutelogic* hyp3rlinx* 9aylas * shadow_00715 * LiquidWorm * thelastvvv *Zigoo.eg |
=======================================================================================================================================
Login or Register to add favorites

File Archive:

March 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Mar 1st
    16 Files
  • 2
    Mar 2nd
    0 Files
  • 3
    Mar 3rd
    0 Files
  • 4
    Mar 4th
    32 Files
  • 5
    Mar 5th
    28 Files
  • 6
    Mar 6th
    42 Files
  • 7
    Mar 7th
    17 Files
  • 8
    Mar 8th
    13 Files
  • 9
    Mar 9th
    0 Files
  • 10
    Mar 10th
    0 Files
  • 11
    Mar 11th
    15 Files
  • 12
    Mar 12th
    19 Files
  • 13
    Mar 13th
    21 Files
  • 14
    Mar 14th
    38 Files
  • 15
    Mar 15th
    15 Files
  • 16
    Mar 16th
    0 Files
  • 17
    Mar 17th
    0 Files
  • 18
    Mar 18th
    10 Files
  • 19
    Mar 19th
    32 Files
  • 20
    Mar 20th
    46 Files
  • 21
    Mar 21st
    16 Files
  • 22
    Mar 22nd
    13 Files
  • 23
    Mar 23rd
    0 Files
  • 24
    Mar 24th
    0 Files
  • 25
    Mar 25th
    12 Files
  • 26
    Mar 26th
    31 Files
  • 27
    Mar 27th
    19 Files
  • 28
    Mar 28th
    42 Files
  • 29
    Mar 29th
    0 Files
  • 30
    Mar 30th
    0 Files
  • 31
    Mar 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close