Noptin < 1.6.5 is susceptible to an open redirect vulnerability. The plugin does not validate the "to" parameter before redirecting the user to its given value, leading to an open redirect issue.Log in to view the POC file snapshot cached by Shenlong Bot
Log in to view