Wise Chat <= 2.6.3 - Reverse Tabnabbing

Strategic Overview

Status
Patched in 2.7
Affected PluginWise Chat
Affected Version< 2.7
CVSS6.1Medium
CVECVE-2019-6780
View all Wise Chat vulnerabilities

Vulnerability Overview

The Wise Chat plugin for WordPress is vulnerable to Reverse Tabnabbing in versions up to, and including, 2.6.3. This is due to mishandling of external links due to omitting noopener and noreferrer. This makes it possible for a chat-using attacker to provide a link that opens a new tab while silently redirecting the original - this can be used to redirect them to a phishing site on the original tab.

Technical Analysis

REMEDIATION: Update to version 2.7, or a newer patched version --- IDENTIFIER: CWE-20 (Improper Input Validation) The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C