Quick Page/Post Redirect Plugin [quick-pagepost-redirect-plugin] < 5.2.4
unknown
[en] Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Anadnet Quick Page/Post Redirect Plugin plugin <= 5.2.3 versions.
- Affected:
- up to 5.2.4
- Fixed in:
- 5.2.4
- Disclosed:
- Aug 8, 2023
CVE-2023-25063 on NVD →
Quick Page/Post Redirect Plugin [quick-pagepost-redirect-plugin] < 5.2.0
unknown
[en] The Quick Page/Post Redirect Plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on the qppr_save_quick_redirect_ajax and qppr_delete_quick_redirect functions in versions up to, and including, 5.1.9. This makes it possible for low-privileged attackers to interact with the pl...
- Affected:
- up to 5.2.0
- Fixed in:
- 5.2.0
- Disclosed:
- Jun 7, 2023
CVE-2020-36699 on NVD →
Quick Page/Post Redirect <= 5.2.3 - Authenticated (Administrator+) Stored Cross-Site Scripting via settings
medium
The Quick Page/Post Redirect plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin settings in versions up to, and including, 5.2.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject...
- CVSS:
- 4.4
- Affected:
- up to 5.2.3
- Fixed in:
- 5.2.4
- Disclosed:
- May 12, 2023
CVE-2023-25063 on NVD →
Quick Page/Post Redirect Plugin <= 5.1.9 - Redirect Security Bypass
medium
The Quick Page/Post Redirect Plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on the qppr_save_quick_redirect_ajax and qppr_delete_quick_redirect functions in versions up to, and including, 5.1.9. This makes it possible for low-privileged attackers to interact with the plugin...
- CVSS:
- 4.3
- Affected:
- up to 5.1.9
- Fixed in:
- 5.2.0
- Disclosed:
- Apr 28, 2020
CVE-2020-36699 on NVD →
Quick Page/Post Redirect Plugin [quick-pagepost-redirect-plugin] < 5.2.0
unknown
Authenticated Settings Change vulnerability discovered by NinTechNet in WordPress Quick Page/Post Redirect plugin (versions <= 5.1.9).
- Affected:
- up to 5.2.0
- Fixed in:
- 5.2.0
- Disclosed:
- Apr 28, 2020
Quick Page/Post Redirect Plugin [quick-pagepost-redirect-plugin] < 5.2.0
unknown
The Quick Page/Post Redirect Plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on the qppr_save_quick_redirect_ajax and qppr_delete_quick_redirect functions in versions up to, and including, 5.1.9. This makes it possible for low-privileged attackers to interact with the plugin...
- Affected:
- up to 5.2.0
- Fixed in:
- 5.2.0
- Disclosed:
- Apr 28, 2020
Quick Page/Post Redirect Plugin [quick-pagepost-redirect-plugin] < 5.0.5
unknown
[en] Cross-site request forgery (CSRF) vulnerability in the Quick Page/Post Redirect plugin before 5.0.5 for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the quickppr_redirects[request][] parameter in the redirect-updat...
- Affected:
- up to 5.0.5
- Fixed in:
- 5.0.5
- Disclosed:
- Jan 5, 2015
CVE-2014-2598 on NVD →
Quick Page/Post Redirect Plugin < 5.0.5 - Cross-Site Request Forgery to Stored Cross-Site Scripting
high
Cross-site request forgery (CSRF) vulnerability in the Quick Page/Post Redirect plugin before 5.0.5 for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the quickppr_redirects[request][] parameter in the redirect-updates pa...
- CVSS:
- 7.1
- Affected:
- up to 5.0.5
- Fixed in:
- 5.0.5
- Disclosed:
- Aug 1, 2014
CVE-2014-2598 on NVD →
Quick Page/Post Redirect Plugin [quick-pagepost-redirect-plugin] < 5.0.4
unknown
WordPress Quick Page/Post Redirect plugin is prone to multiple vulnerabilities, such as CSRF and XSS. Because of this vulnerabilities, an admin user can be persuaded to visit a URL of the attacker’s choosing, the attacker can insert arbitrary JavaScript into an admin page. In that way the admin's browser can create or...
- Affected:
- up to 5.0.4
- Fixed in:
- 5.0.4
- Disclosed:
- Apr 14, 2014
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database