plugin

Eps 301 Redirects Vulnerabilities

8 known security issues reported for the Eps 301 Redirects WordPress plugin. Most recent disclosed Mar 9, 2023.

1 high 2 medium

Running Eps 301 Redirects on your site? Check whether your installed version is affected.

Scan your site free

301 Redirects &#8211; Easy Redirect Manager [eps-301-redirects] < 2.73

unknown

Update the WordPress 301 Redirects plugin to the latest available version (at least 2.73). Unknown discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress 301 Redirects Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted actions under their c...

Affected:
up to 2.73
Fixed in:
2.73
Disclosed:
Mar 9, 2023

301 Redirects - Easy Redirect Manager <= 2.72 - Cross-Site Request Forgery via dismiss_notice

medium

The 301 Redirects - Easy Redirect Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.73. This is due to missing or incorrect nonce validation on the 'dismiss_notice' function. This makes it possible for unauthenticated attackers to dismiss the plugin's admin not...

CVSS:
4.3
Affected:
up to 2.72
Fixed in:
2.73
Disclosed:
Mar 8, 2023

301 Redirects &#8211; Easy Redirect Manager [eps-301-redirects] < 2.73

unknown

The 301 Redirects - Easy Redirect Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.73. This is due to missing or incorrect nonce validation on the 'dismiss_notice' function. This makes it possible for unauthenticated attackers to dismiss the plugin's admin not...

Affected:
up to 2.73
Fixed in:
2.73
Disclosed:
Mar 8, 2023

301 Redirects &#8211; Easy Redirect Manager [eps-301-redirects] < 2.51

unknown

[en] Unvaludated input in the 301 Redirects - Easy Redirect Manager WordPress plugin, versions before 2.51, did not sanitise its "Redirect From" column when importing a CSV file, allowing high privilege users to perform SQL injections.

Affected:
up to 2.51
Fixed in:
2.51
Disclosed:
Mar 18, 2021

CVE-2021-24142 on NVD →

301 Redirects - Easy Redirect Manager < 2.51 - SQL Injection

high

Unvaludated input in the 301 Redirects - Easy Redirect Manager WordPress plugin, versions before 2.51, did not sanitise its "Redirect From" column when importing a CSV file, allowing high privilege users to perform SQL injections.

CVSS:
7.2
Affected:
up to 2.51
Fixed in:
2.51
Disclosed:
Jan 18, 2021

CVE-2021-24142 on NVD →

301 Redirects &#8211; Easy Redirect Manager [eps-301-redirects] < 2.45

unknown

Authenticated Arbitrary Redirect Injection, XSS, and CSRF vulnerabilities found by Chloe Chamberland in WordPress 301 Redirects plugin (versions <= 2.40).

Affected:
up to 2.45
Fixed in:
2.45
Disclosed:
Dec 20, 2019

301 Redirects - Easy Redirect Manager <= 2.40 - Missing Authorization

medium

The "301 Redirects - Easy Redirect Manager" plugin before 2.45 for WordPress allows users (with subscriber or greater access) to modify, delete, or inject redirect rules, and exploit XSS, with the /admin-ajax.php?action=eps_redirect_save and /admin-ajax.php?action=eps_redirect_delete actions. This could result in a los...

CVSS:
6.5
Affected:
up to 2.40
Fixed in:
2.45
Disclosed:
Dec 19, 2019

CVE-2019-19915 on NVD →

301 Redirects &#8211; Easy Redirect Manager [eps-301-redirects] < 2.45

unknown

[en] The "301 Redirects - Easy Redirect Manager" plugin before 2.45 for WordPress allows users (with subscriber or greater access) to modify, delete, or inject redirect rules, and exploit XSS, with the /admin-ajax.php?action=eps_redirect_save and /admin-ajax.php?action=eps_redirect_delete actions. This could result in...

Affected:
up to 2.45
Fixed in:
2.45
Disclosed:
Dec 19, 2019

CVE-2019-19915 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database