==================================================================================================================================== | # Title : WordPress -WPtouch 3.8.2 Open Redirect Vulnerability | | # Author : indoushka | | # Tested on : windows 10 Français V.(Pro) / browser : Mozilla firefox 66.0(64-bit) | | # Vendor : https://wordpress.org/plugins/wptouch/ | | # Dork : wp-content/plugins/wptouch/ | ==================================================================================================================================== P0C : == Description == WPtouch is a mobile plugin for WordPress that automatically adds a simple and elegant mobile theme for mobile visitors to your WordPress website. When you activate the plugin and set it up, it allows the site visitor to view it according to the device used for browsing However, when connected to a mobile device, Plugins allows you to switch the display between a desktop or a mobile device Desktop browsing does not allow you to convert But if we use the payload then it is possible. This URL Redirection vulnerability allows remote Attackers to redirect users to arbitrary websites and conduct phishing attacks [+] Dorking İn Google Or Other Search Enggine. [+] Use payload : /?wptouch_switch=desktop&redirect=https://packetstormsecurity.com/&nonce=e9c03107dd [+] http://127.0.0.1/pepsynet/?wptouch_switch=desktop&redirect=https://packetstormsecurity.com/&nonce=e9c03107dd Greetings to :========================================================================================================================= jericho * Larry W. Cashdollar * brutelogic* hyp3rlinx* 9aylas * shadow_00715 * LiquidWorm * thelastvvv *Zigoo.eg | =======================================================================================================================================