WordPress StageShow plugin before 5.0.9 contains an open redirect vulnerability in the Redirect function in stageshow_redirect.php. A remote attacker can redirect users to arbitrary web sites and conduct phishing attacks via a malicious URL in the url parameter.
id: CVE-2015-5461
info:
name: WordPress StageShow <5.0.9 - Open Redirect
author: 0x_Akoko
sev
...