CVE Vulnerabilities

CVE-2022-2600

Published: Aug 22, 2022 | Modified: Aug 23, 2022
CVSS 3.x
5.4
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

The Auto-hyperlink URLs WordPress plugin through 5.4.1 does not set rel=noopener noreferer on generated links, which can lead to Tab Nabbing by giving the target site access to the source tab through the window.opener DOM object.

Affected Software

Name Vendor Start Version End Version
Auto-hyperlink_urls Auto-hyperlink_urls_project * 5.4.1 (including)

References