This really wouldn’t have anything to do with WordPress intrinsically. It would be related to some plugin or code that passes values based on post data or anything that can request back-end HTTP to another application. The problem is you are open for XSS and SQL injection.
Do you have user input fields i.e. POST data that is passed without encoding the URL properly? Any point of user input should be sanitized.
Check out http://www.w3schools.com/tags/ref_urlencode.asp for reference.
I found an example of this here – https://stackoverflow.com/questions/19809142/http-parameter-pollution
Related Posts:
- Should a 502 HTTP status code be used if a proxy receives no response at all?
- What is the difference between a URI, a URL and a URN?
- HTTP Status 504
- What is the difference between POST and GET? [duplicate]
- Do I need Content-Type: application/octet-stream for file download?
- Problem HTTP error 403 in Python 3 Web Scraping
- application/x-www-form-urlencoded or multipart/form-data?
- Problem HTTP error 403 in Python 3 Web Scraping
- application/x-www-form-urlencoded or multipart/form-data?
- Is 418 “I’m a teapot” really an HTTP response code?
- How to define the basic HTTP authentication using cURL correctly?
- How to define the basic HTTP authentication using cURL correctly?
- “Cannot GET /” with Connect on Node.js
- “CAUTION: provisional headers are shown” in Chrome debugger
- What’s the difference between a POST and a PUT HTTP REQUEST?
- How do I send a POST request with PHP?
- Why is it said that “HTTP is a stateless protocol”?
- What’s the difference between using application/csv vs text/csv? [duplicate]
- What are all the possible values for HTTP “Content-Type” header?
- What is the difference between PUT, POST and PATCH?
- What’s the difference between “Request Payload” vs “Form Data” as seen in Chrome dev tools Network tab
- Exception in thread “main” java.net.NoRouteToHostException: No route to host
- ndroid 8: Cleartext HTTP traffic not permitted
- Can PHP cURL retrieve response headers AND body in a single request?
- Setting Curl’s Timeout in PHP
- How are parameters sent in an HTTP POST request?
- Why am I suddenly getting a “Blocked loading mixed active content” issue in Firefox?
- wget: unable to resolve host address `http’
- Are HTTP headers case-sensitive?
- When looking at the differences between X-Auth-Token vs Authorization headers, which is preferred?
- Does WordPress send data about your blog to WordPress.org or Automattic?
- Hiding WordPress REST API v2 endpoints from public viewing
- Does WordPress only support HTTP 1.1?
- How do I troubleshoot responses with WP HTTP API?
- Is curl required?
- The resource was preloaded using link preload but not used within a few seconds
- using wp_remote_get to retrieve own url on local host
- Using wp-cron in backpress – problems with wp_remote_post, fsockopen error
- Running index.php from command line & load balancer health checks
- Enable CORS in wordpress
- Change port of wordpress
- How to get value of custom http header?
- Several times request to load plugins when sending one request
- why is $_REQUESt[‘redirect_to’] empty?
- Get “HTTP/1.1 406 Not Acceptable” when accesing my website with Delphi Indy Control
- WordPress HTTP 500 Error “page isn’t working”
- What’s the point in having “www” in a URL?
- For what is the “.well-known”-folder?
- Human readable format for http headers with tcpdump
- How to make wireshark filter POST-requests only?
- Image file urls still point to http instead of https
- What is the difference between POST and PUT in HTTP?
- Chrome hangs after certain amount of data transfered – waiting for available socket
- Use of PUT vs PATCH methods in REST API real life scenarios
- How to download a file over HTTP?
- Axios Delete request with body and headers?
- How to do a PUT request with cURL?
- What does HTTP/1.1 302 mean exactly?
- Error: No default engine was specified and no extension was provided
- PHP + curl, HTTP POST sample code?
- Response to preflight request doesn’t pass access control check
- Uri not Absolute exception getting while calling Restful Webservice
- urllib2.HTTPError: HTTP Error 403: Forbidden
- Getting “Handshake failed…unexpected packet format” when using WebClient.UploadFile() with “https” when the server has a valid SSL certificate
- Simple HTTP server in Java using only Java SE API
- Https to http redirect using htaccess
- “Cross origin requests are only supported for HTTP.” error when loading a local file
- HTTP status code 0 – Error Domain=NSURLErrorDomain?
- Where to get information about array fields in $_REQUEST?
- How do I use the ‘http_request_host_is_external’ filter
- Serving HTTP and HTTPS from one installation
- force http canonical tag on https pages
- How can I change HTTP headers only to posts of a specific category from a plugin
- How to get title tag of an external page with http api?
- Broken urls with http site and https wp-admin
- Can I use HTTP POSTs? Is there a better alternative?
- Can’t login to Dashboard when changing site URL to HTTPS
- 403 error on admin login page
- Is it possible to access the wp-admin from one instance while keeping WP_HOME pointing to the balancing url?
- No ‘Access-Control-Allow-Origin’ header is present [closed]
- wrong media url in wordpress
- Allow non-SSL pages to use https or Force non-SSL pages to http?
- Any any insecure http:// URLs left in wordpress?
- 404/500 error on content images if Referer header is from another domain [closed]
- Implementing a URL Shortener
- How to convert srcset links from https to http?
- Why does WP HTTP API switch the method (POST/PURGE) to GET when redirecting (302)?
- Local WordPress with WAMP downloads files out of Nowhere
- Need workaround for insecure XMLHttpRequest endpoint request
- Reading URL Parameters
- Display values of current POST request on page
- Website Migration (with https) to a new domain(http)
- Understanding Redirects
- Staging Session Randomly Switched from Secure (https) to Not Secure
- Sudden Upload HTTP errors, PHP uploads and memory limits are already to high to my taste. Anything else?
- WordPress Rest API Error 502
- Configure WordPress to listen on a port other than 80
- Random HTTP 500 error in WordPress
- Nice font not working when http to https – SSL Issue
- The plain HTTP request was sent to HTTPS port in wordpress [closed]