CVE-2019-16220
—CVSS 3.1
6.1 medium
EPSS
3%p84
Published
()
Modified
Description
In WordPress before 5.2.3, validation and sanitization of a URL in wp_validate_redirect in wp-includes/pluggable.php could lead to an open redirect if a provided URL path does not start with a forward slash.
In the news0 stories
No ingested article mentions this CVE yet.