Vulnerabilities > CVE-2022-1583 - Use of Web Link to Untrusted Target with window.opener Access vulnerability in Webfactoryltd External Links in NEW Window / NEW TAB

047910
CVSS 6.5 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
network
low complexity
webfactoryltd
CWE-1022

Summary

The External Links in New Window / New Tab WordPress plugin before 1.43 does not ensure window.opener is set to "null" when links to external sites are clicked, which may enable tabnabbing attacks to occur.