The Auto-hyperlink URLs WordPress plugin through 5.4.1...
Moderate severity
Unreviewed
Published
Aug 23, 2022
to the GitHub Advisory Database
•
Updated Jan 28, 2023
Description
Published by the National Vulnerability Database
Aug 22, 2022
Published to the GitHub Advisory Database
Aug 23, 2022
Last updated
Jan 28, 2023
The Auto-hyperlink URLs WordPress plugin through 5.4.1 does not set rel="noopener noreferer" on generated links, which can lead to Tab Nabbing by giving the target site access to the source tab through the window.opener DOM object.
References