301 Redirects – Easy Redirect Manager [eps-301-redirects] < 2.73
unknown
Update the WordPress 301 Redirects plugin to the latest available version (at least 2.73).
Unknown discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress 301 Redirects Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted actions under their c...
- Affected:
- up to 2.73
- Fixed in:
- 2.73
- Disclosed:
- Mar 9, 2023
301 Redirects - Easy Redirect Manager <= 2.72 - Cross-Site Request Forgery via dismiss_notice
medium
The 301 Redirects - Easy Redirect Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.73. This is due to missing or incorrect nonce validation on the 'dismiss_notice' function. This makes it possible for unauthenticated attackers to dismiss the plugin's admin not...
- CVSS:
- 4.3
- Affected:
- up to 2.72
- Fixed in:
- 2.73
- Disclosed:
- Mar 8, 2023
301 Redirects – Easy Redirect Manager [eps-301-redirects] < 2.73
unknown
The 301 Redirects - Easy Redirect Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.73. This is due to missing or incorrect nonce validation on the 'dismiss_notice' function. This makes it possible for unauthenticated attackers to dismiss the plugin's admin not...
- Affected:
- up to 2.73
- Fixed in:
- 2.73
- Disclosed:
- Mar 8, 2023
301 Redirects – Easy Redirect Manager [eps-301-redirects] < 2.51
unknown
[en] Unvaludated input in the 301 Redirects - Easy Redirect Manager WordPress plugin, versions before 2.51, did not sanitise its "Redirect From" column when importing a CSV file, allowing high privilege users to perform SQL injections.
- Affected:
- up to 2.51
- Fixed in:
- 2.51
- Disclosed:
- Mar 18, 2021
CVE-2021-24142 on NVD →
301 Redirects - Easy Redirect Manager < 2.51 - SQL Injection
high
Unvaludated input in the 301 Redirects - Easy Redirect Manager WordPress plugin, versions before 2.51, did not sanitise its "Redirect From" column when importing a CSV file, allowing high privilege users to perform SQL injections.
- CVSS:
- 7.2
- Affected:
- up to 2.51
- Fixed in:
- 2.51
- Disclosed:
- Jan 18, 2021
CVE-2021-24142 on NVD →
301 Redirects – Easy Redirect Manager [eps-301-redirects] < 2.45
unknown
Authenticated Arbitrary Redirect Injection, XSS, and CSRF vulnerabilities found by Chloe Chamberland in WordPress 301 Redirects plugin (versions <= 2.40).
- Affected:
- up to 2.45
- Fixed in:
- 2.45
- Disclosed:
- Dec 20, 2019
301 Redirects - Easy Redirect Manager <= 2.40 - Missing Authorization
medium
The "301 Redirects - Easy Redirect Manager" plugin before 2.45 for WordPress allows users (with subscriber or greater access) to modify, delete, or inject redirect rules, and exploit XSS, with the /admin-ajax.php?action=eps_redirect_save and /admin-ajax.php?action=eps_redirect_delete actions. This could result in a los...
- CVSS:
- 6.5
- Affected:
- up to 2.40
- Fixed in:
- 2.45
- Disclosed:
- Dec 19, 2019
CVE-2019-19915 on NVD →
301 Redirects – Easy Redirect Manager [eps-301-redirects] < 2.45
unknown
[en] The "301 Redirects - Easy Redirect Manager" plugin before 2.45 for WordPress allows users (with subscriber or greater access) to modify, delete, or inject redirect rules, and exploit XSS, with the /admin-ajax.php?action=eps_redirect_save and /admin-ajax.php?action=eps_redirect_delete actions. This could result in...
- Affected:
- up to 2.45
- Fixed in:
- 2.45
- Disclosed:
- Dec 19, 2019
CVE-2019-19915 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database