header-logo
Suggest Exploit
vendor:
WPtouch
by:
MaKyOtOx
7.5
CVSS
HIGH
URL redirection
601
CWE
Product Name: WPtouch
Affected Version From: 1.9.27
Affected Version To: 1.9.27
Patch Exists: YES
Related CWE: 0-Day
CPE: a:bravenewcode:wptouch:1.9.27
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: WhatEver OS
2011

0-Day WPtouch WordPress Plugin 1.9.27 URL redirection

A 0-day vulnerability exists in the WPtouch WordPress Plugin 1.9.27, which allows attackers to redirect users to malicious websites. An attacker can craft a malicious URL with the ‘wptouch_view’ and ‘wptouch_redirect’ parameters, which can be used to redirect users to a malicious website. The malicious URL can be used in phishing campaigns to steal user credentials.

Mitigation:

Users should update to the latest version of the WPtouch WordPress Plugin and ensure that all plugins are up to date.
Source

Exploit-DB raw data:

Hello , that's a 0day on the must downloaded WordPress plugin.

# Exploit Title: 0-Day WPtouch WordPress Plugin 1.9.27 URL redirection
# Google Dork: intext:"Powered by Wordpress + WPtouch" (with iphone/android
User-Agent)
# Author: MaKyOtOx (special Pwet to ansx & Zizounette for #bitcoins)
# Date: 20/06/2011
# Software Link: http://wordpress.org/extend/plugins/wptouch/
# Version: 1.9.27 (not tested on previous versions)
# Tested on: WhatEver OS
# CVE : 0-Day

http://site.com/?wptouch_view=normal&wptouch_redirect=.attacker-site.com

# It would redirect to : http://site.com.attacker-site.com :)