All 404 Redirect to Homepage & Broken images Redirection <= 2.0 - Cross-Site Scripting
medium
The All 404 Redirect to Homepage & Broken images Redirection plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 2.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-l...
- CVSS:
- 5.5
- Affected:
- up to 2.0
- Fixed in:
- 2.1
- Disclosed:
- Jun 1, 2021
All 404 Redirect to Homepage [all-404-redirect-to-homepage] < 2.1
unknown
Authenticated Stored Cross-Site Scripting (XSS) vulnerability discovered by WPScanTeam in WordPress All 404 Redirect to Homepage plugin (versions <= 1.21).
- Affected:
- up to 2.1
- Fixed in:
- 2.1
- Disclosed:
- Jun 1, 2021
All 404 Redirect to Homepage [all-404-redirect-to-homepage] < 2.1
unknown
The All 404 Redirect to Homepage & Broken images Redirection plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 2.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-l...
- Affected:
- up to 2.1
- Fixed in:
- 2.1
- Disclosed:
- Jun 1, 2021
All 404 Redirect to Homepage [all-404-redirect-to-homepage] < 1.21
unknown
[en] The tab parameter of the settings page of the All 404 Redirect to Homepage WordPress plugin before 1.21 was vulnerable to an authenticated reflected Cross-Site Scripting (XSS) issue as user input was not properly sanitised before being output in an attribute.
- Affected:
- up to 1.21
- Fixed in:
- 1.21
- Disclosed:
- May 17, 2021
CVE-2021-24326 on NVD →
All 404 Redirect to Homepage [all-404-redirect-to-homepage] < 1.21
unknown
Authenticated Persistent Cross-Site Scripting (XSS) vulnerability discovered by m0ze (Patchstack Red Team) in WordPress All 404 Redirect to Homepage plugin (versions <= 1.20).
- Affected:
- up to 1.21
- Fixed in:
- 1.21
- Disclosed:
- Apr 21, 2021
All 404 Redirect to Homepage [all-404-redirect-to-homepage] < 1.21
unknown
Authenticated Reflected Cross-Site Scripting (XSS) vulnerability discovered by m0ze (Patchstack Red Team) in WordPress All 404 Redirect to Homepage plugin (versions <= 1.20).
- Affected:
- up to 1.21
- Fixed in:
- 1.21
- Disclosed:
- Apr 21, 2021
All 404 Redirect to Homepage < 1.21 - Reflected Cross-Site Scripting via tab Parameter
medium
The tab parameter of the settings page of the All 404 Redirect to Homepage WordPress plugin before 1.21 was vulnerable to an authenticated reflected Cross-Site Scripting (XSS) issue as user input was not properly sanitised before being output in an attribute.
- CVSS:
- 6.1
- Affected:
- up to 1.21
- Fixed in:
- 1.21
- Disclosed:
- Apr 16, 2021
CVE-2021-24326 on NVD →
All 404 Redirect to Homepage [all-404-redirect-to-homepage] < 2.1
unknown
The plugin (v1.21) attempted to fix a Stored Cross-Site scripting issue in its "Redirect All 404 page to" settings, however the fix is insufficient, still allowing the issue to be triggered. This could allow high privilege users (even with the unfiltered_html disabled) to use malicious payloads in it, leading...
- Affected:
- up to 2.1
- Fixed in:
- 2.1
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database