CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 5.4. It affects WordPress.
CVE
CVE-2022-2600
Severity
MEDIUM
CVSS
5.4
EPSS
0.52%
WordPress
Original NVD Description
The Auto-hyperlink URLs WordPress plugin through 5.4.1 does not set rel="noopener noreferer" on generated links, which can lead to Tab Nabbing by giving the target site access to the source tab through the window.opener DOM object.