plugin

All 404 Redirect To Homepage Vulnerabilities

8 known security issues reported for the All 404 Redirect To Homepage WordPress plugin. Most recent disclosed Jun 1, 2021.

2 medium

Running All 404 Redirect To Homepage on your site? Check whether your installed version is affected.

Scan your site free

All 404 Redirect to Homepage & Broken images Redirection <= 2.0 - Cross-Site Scripting

medium

The All 404 Redirect to Homepage & Broken images Redirection plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 2.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-l...

CVSS:
5.5
Affected:
up to 2.0
Fixed in:
2.1
Disclosed:
Jun 1, 2021

All 404 Redirect to Homepage [all-404-redirect-to-homepage] < 2.1

unknown

Authenticated Stored Cross-Site Scripting (XSS) vulnerability discovered by WPScanTeam in WordPress All 404 Redirect to Homepage plugin (versions <= 1.21).

Affected:
up to 2.1
Fixed in:
2.1
Disclosed:
Jun 1, 2021

All 404 Redirect to Homepage [all-404-redirect-to-homepage] < 2.1

unknown

The All 404 Redirect to Homepage & Broken images Redirection plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 2.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-l...

Affected:
up to 2.1
Fixed in:
2.1
Disclosed:
Jun 1, 2021

All 404 Redirect to Homepage [all-404-redirect-to-homepage] < 1.21

unknown

[en] The tab parameter of the settings page of the All 404 Redirect to Homepage WordPress plugin before 1.21 was vulnerable to an authenticated reflected Cross-Site Scripting (XSS) issue as user input was not properly sanitised before being output in an attribute.

Affected:
up to 1.21
Fixed in:
1.21
Disclosed:
May 17, 2021

CVE-2021-24326 on NVD →

All 404 Redirect to Homepage [all-404-redirect-to-homepage] < 1.21

unknown

Authenticated Persistent Cross-Site Scripting (XSS) vulnerability discovered by m0ze (Patchstack Red Team) in WordPress All 404 Redirect to Homepage plugin (versions <= 1.20).

Affected:
up to 1.21
Fixed in:
1.21
Disclosed:
Apr 21, 2021

All 404 Redirect to Homepage [all-404-redirect-to-homepage] < 1.21

unknown

Authenticated Reflected Cross-Site Scripting (XSS) vulnerability discovered by m0ze (Patchstack Red Team) in WordPress All 404 Redirect to Homepage plugin (versions <= 1.20).

Affected:
up to 1.21
Fixed in:
1.21
Disclosed:
Apr 21, 2021

All 404 Redirect to Homepage < 1.21 - Reflected Cross-Site Scripting via tab Parameter

medium

The tab parameter of the settings page of the All 404 Redirect to Homepage WordPress plugin before 1.21 was vulnerable to an authenticated reflected Cross-Site Scripting (XSS) issue as user input was not properly sanitised before being output in an attribute.

CVSS:
6.1
Affected:
up to 1.21
Fixed in:
1.21
Disclosed:
Apr 16, 2021

CVE-2021-24326 on NVD →

All 404 Redirect to Homepage [all-404-redirect-to-homepage] < 2.1

unknown

The plugin (v1.21) attempted to fix a Stored Cross-Site scripting issue in its &quot;Redirect All 404 page to&quot; settings, however the fix is insufficient, still allowing the issue to be triggered. This could allow high privilege users (even with the unfiltered_html disabled) to use malicious payloads in it, leading...

Affected:
up to 2.1
Fixed in:
2.1

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database