-------------------------------------------
WPBounce WordPress plugin Open Redirect
By SonnySpooks
-------------------------------------------
1. [About App]
-------------------------------------------
WPBounce is a webapp that displays offers
To users leaving the site to increase sales
and Traffic.
-------------------------------------------
2. [Issue With It]
-------------------------------------------
The redirector.php file in the
/AND-AntiBounce/ directory has a param
"url=" that leaves 100s of sites that
Use WPBounce easily utilzied for
Open Redirects
-------------------------------------------
3. [Replication of attack]
-------------------------------------------
Example: "Site.com/wp-content/plugins/AND-AntiBounce/redirector.php?url="
-------------------------------------------
________
/\ \
/ \ \
/ \ \
/ \_______\
\ / /
___\ / ____/___
/\ \ / /\ \
/ \ \/___/ \ \
/ \ \ \ \
/ \_______\ \_______\
\ / / / /
\ / / / /
\ / /\ / /
\/_______/ \/_______/
-------------------------------------------