plugin

Redirect Redirection Vulnerabilities

64 known security issues reported for the Redirect Redirection WordPress plugin. Most recent disclosed Dec 13, 2024.

30 medium

Running Redirect Redirection on your site? Check whether your installed version is affected.

Scan your site free

Redirection [redirect-redirection] < 1.1.4

unknown

[en] Missing Authorization vulnerability in social share pro Social Share Icons & Social Share Buttons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Social Share Icons & Social Share Buttons: from n/a through 3.5.7.

Affected:
up to 1.1.4
Fixed in:
1.1.4
Disclosed:
Dec 13, 2024

CVE-2023-38514 on NVD →

Inisev Analyst Module <= Various Versions - Missing Authorization

medium

Multiple plugins and/or themes by Inisev for WordPress are vulnerable to unauthorized access due to a missing capability check on several functions in various versions. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform unauthorized actions.

CVSS:
4.3
Affected:
up to 1.1.9
Fixed in:
1.2.0
Disclosed:
Apr 10, 2024

CVE-2024-31435 on NVD →

Redirection [redirect-redirection] < 1.1.4

unknown

[en] Several plugins for WordPress by Inisev are vulnerable to unauthorized installation of plugins due to a missing capability check on the handle_installation function that is called via the inisev_installation AJAX aciton in various versions. This makes it possible for authenticated attackers with minimal permission...

Affected:
up to 1.1.4
Fixed in:
1.1.4
Disclosed:
Jul 28, 2023

CVE-2023-0958 on NVD →

Redirection [redirect-redirection] < 1.1.4

unknown

[en] Several plugins for WordPress by Inisev are vulnerable to Cross-Site Request Forgery to unauthorized installation of plugins due to a missing nonce check on the handle_installation function that is called via the inisev_installation AJAX aciton in various versions. This makes it possible for unauthenticated attack...

Affected:
up to 1.1.4
Fixed in:
1.1.4
Disclosed:
Jul 28, 2023

CVE-2023-3977 on NVD →

Inisev Plugins (Various Versions) - Missing Authorization on handle_installation function

medium

Several plugins for WordPress by Inisev are vulnerable to unauthorized installation of plugins due to a missing capability check on the handle_installation function that is called via the inisev_installation AJAX aciton in various versions. This makes it possible for authenticated attackers with minimal permissions, su...

CVSS:
4.3
Affected:
up to 1.1.3
Fixed in:
1.1.4
Disclosed:
Jul 27, 2023

CVE-2023-0958 on NVD →

Inisev Plugins (Various Versions) - Cross-Site Request Forgery on handle_installation function

medium

Several plugins for WordPress by Inisev are vulnerable to Cross-Site Request Forgery to unauthorized installation of plugins due to a missing nonce check on the handle_installation function that is called via the inisev_installation AJAX aciton in various versions. This makes it possible for unauthenticated attackers t...

CVSS:
4.3
Affected:
up to 1.1.3
Fixed in:
1.1.4
Disclosed:
Jul 27, 2023

CVE-2023-3977 on NVD →

Redirection [redirect-redirection] < 1.1.5

unknown

[en] The Redirection WordPress plugin before 1.1.5 does not have CSRF checks in the uninstall action, which could allow attackers to make logged in admins delete all the redirections through a CSRF attack.

Affected:
up to 1.1.5
Fixed in:
1.1.5
Disclosed:
Apr 17, 2023

CVE-2023-1331 on NVD →

Redirection [redirect-redirection] < 1.1.5

unknown

[en] The Redirection WordPress plugin before 1.1.4 does not add nonce verification in place when adding the redirect, which could allow attackers to add redirects via a CSRF attack.

Affected:
up to 1.1.5
Fixed in:
1.1.5
Disclosed:
Apr 3, 2023

CVE-2023-1330 on NVD →

Redirection <= 1.1.4 - Cross-Site Request Forgery to Plugin Reset

medium

The Redirection plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.4. This is due to missing or incorrect nonce validation on the 'uninstall' function hooked via admin_post. This makes it possible for unauthenticated attackers to deactivate and reset the plugin via a...

CVSS:
5.4
Affected:
up to 1.1.4
Fixed in:
1.1.5
Disclosed:
Mar 21, 2023

CVE-2023-1331 on NVD →

Redirection [redirect-redirection] < 1.1.5

unknown

Update the WordPress Redirect Redirection plugin to the latest available version (at least 1.1.5). Unknown discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress Redirect Redirection Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted action...

Affected:
up to 1.1.5
Fixed in:
1.1.5
Disclosed:
Mar 15, 2023

Redirect Redirection <= 1.1.4 - Cross-Site Request Forgery to Plugin De-Installation

medium

The Redirect Redirection plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.4. This is due to missing nonce validation on the uninstall() function called via an admin_post hook. This makes it possible for unauthenticated attackers to uninstall the plugin via a forged...

CVSS:
5.4
Affected:
up to 1.1.4
Fixed in:
1.1.5
Disclosed:
Mar 14, 2023

Redirection [redirect-redirection] < 1.1.5

unknown

The Redirect Redirection plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.4. This is due to missing nonce validation on the uninstall() function called via an admin_post hook. This makes it possible for unauthenticated attackers to uninstall the plugin via a forged...

Affected:
up to 1.1.5
Fixed in:
1.1.5
Disclosed:
Mar 14, 2023

Redirect Redirection <= 1.1.3 - Missing Authorization in 'LoadTab' function

medium

The Redirect Redirection plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the LoadTab function called via an AJAX action in versions up to, and including, 1.1.3. This makes it possible for authenticated attackers with subscriber-level access, and above, to load tabs...

CVSS:
4.3
Affected:
up to 1.1.3
Fixed in:
1.1.4
Disclosed:
Feb 22, 2023

Redirect Redirection <= 1.1.3 - Cross-Site Request Forgery via 'addRedirect' function

medium

The Redirect Redirection plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3. This is due to missing or incorrect nonce validation on the addRedirect function. This makes it possible for unauthenticated attackers to add redirects, via a forged request granted they ca...

CVSS:
4.3
Affected:
up to 1.1.3
Fixed in:
1.1.4
Disclosed:
Feb 22, 2023

CVE-2023-1330 on NVD →

Redirection [redirect-redirection] < 1.1.4

unknown

The Redirect Redirection plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the LoadTab function called via an AJAX action in versions up to, and including, 1.1.3. This makes it possible for authenticated attackers with subscriber-level access, and above, to load tabs...

Affected:
up to 1.1.4
Fixed in:
1.1.4
Disclosed:
Feb 22, 2023

Redirection [redirect-redirection] < 1.1.4

unknown

Update the WordPress Redirect Redirection plugin to the latest available version (at least 1.1.4). WordFence discovered and reported this Broken Access Control vulnerability in WordPress Redirect Redirection Plugin. This vulnerability has been fixed in version 1.1.4.

Affected:
up to 1.1.4
Fixed in:
1.1.4
Disclosed:
Feb 22, 2023

Redirection [redirect-redirection] < 1.1.4

unknown

The Redirect Redirection plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3. This is due to missing or incorrect nonce validation on the addRedirect function. This makes it possible for unauthenticated attackers to add redirects, via a forged request granted they ca...

Affected:
up to 1.1.4
Fixed in:
1.1.4
Disclosed:
Feb 22, 2023

Redirect Redirection <= 1.1.3 - Missing Authorization in 'loadRedirectSettings' function

medium

The Redirect Redirection plugin for WordPress is vulnerable to unauthorized disclosure of data due to a missing capability check on the loadRedirectSettings function called via an AJAX action in versions up to, and including, 1.1.3. This makes it possible for authenticated attackers with subscriber-level access, and ab...

CVSS:
5.3
Affected:
up to 1.1.3
Fixed in:
1.1.4
Disclosed:
Feb 21, 2023

Redirect Redirection <= 1.1.3 - Missing Authorization in 'logPageContent' function

medium

The Redirect Redirection plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the logPageContent function called via an AJAX action in versions up to, and including, 1.1.3. This makes it possible for authenticated attackers with subscriber-level access, and above, to vi...

CVSS:
4.3
Affected:
up to 1.1.3
Fixed in:
1.1.4
Disclosed:
Feb 21, 2023

Redirect Redirection <= 1.1.3 - Missing Authorization in 'bulkDelete' function

medium

The Redirect Redirection plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the bulkDelete function called via an AJAX action in versions up to, and including, 1.1.3. This makes it possible for authenticated attackers with subscriber-level access, and above, to...

CVSS:
4.3
Affected:
up to 1.1.3
Fixed in:
1.1.4
Disclosed:
Feb 21, 2023

Redirect Redirection <= 1.1.3 - Missing Authorization in 'statusBulkEdit' function

medium

The Redirect Redirection plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the statusBulkEdit function called via an AJAX action in versions up to, and including, 1.1.3. This makes it possible for authenticated attackers with subscriber-level access, and above,...

CVSS:
4.3
Affected:
up to 1.1.3
Fixed in:
1.1.4
Disclosed:
Feb 21, 2023

Redirect Redirection <= 1.1.3 - Missing Authorization in 'saveRedirectSettings' function

medium

The Redirect Redirection plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the saveRedirectSettings function called via an AJAX action in versions up to, and including, 1.1.3. This makes it possible for authenticated attackers with subscriber-level access, and...

CVSS:
4.3
Affected:
up to 1.1.3
Fixed in:
1.1.4
Disclosed:
Feb 21, 2023

Redirect Redirection <= 1.1.3 - Cross-Site Request Forgery via 'instantEditRedirect' function

medium

The Redirect Redirection plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3. This is due to missing or incorrect nonce validation on the instantEditRedirect function. This makes it possible for unauthenticated attackers to edit redirects via a forged request granted...

CVSS:
4.3
Affected:
up to 1.1.3
Fixed in:
1.1.4
Disclosed:
Feb 21, 2023

Redirect Redirection <= 1.1.3 - Missing Authorization in 'redirectionPageContent' function

medium

The Redirect Redirection plugin for WordPress is vulnerable to unauthorized disclosure of data due to a missing capability check on the redirectionPageContent function called via an AJAX action in versions up to, and including, 1.1.3. This makes it possible for authenticated attackers with subscriber-level access, and...

CVSS:
4.3
Affected:
up to 1.1.3
Fixed in:
1.1.4
Disclosed:
Feb 21, 2023

Redirect Redirection <= 1.1.3 - Cross-Site Request Forgery via 'statusBulkEdit' function

medium

The Redirect Redirection plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3. This is due to missing or incorrect nonce validation on the statusBulkEdit function. This makes it possible for unauthenticated attackers to bulk edit redirect rules, via a forged request g...

CVSS:
4.3
Affected:
up to 1.1.3
Fixed in:
1.1.4
Disclosed:
Feb 21, 2023

Redirect Redirection <= 1.1.3 - Missing Authorization in 'addRedirect' function

medium

The Redirect Redirection plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the addRedirect function called via an AJAX action in versions up to, and including, 1.1.3. This makes it possible for authenticated attackers with subscriber-level access, and above, to...

CVSS:
4.3
Affected:
up to 1.1.3
Fixed in:
1.1.4
Disclosed:
Feb 21, 2023

Redirect Redirection <= 1.1.3 - Missing Authorization in 'deleteRedirect' function

medium

The Redirect Redirection plugin for WordPress is vulnerable to unauthorized modification of settings due to a missing capability check on the deleteRedirect function called via an AJAX action in versions up to, and including, 1.1.3. This makes it possible for authenticated attackers with subscriber-level access, and ab...

CVSS:
4.3
Affected:
up to 1.1.3
Fixed in:
1.1.4
Disclosed:
Feb 21, 2023

Redirect Redirection <= 1.1.3 - Cross-Site Request Forgery via 'SaveSettings' function

medium

The Redirect Redirection plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3. This is due to missing or incorrect nonce validation on the SaveSettings function. This makes it possible for unauthenticated attackers to update the plugin's settings, via a forged request...

CVSS:
4.3
Affected:
up to 1.1.3
Fixed in:
1.1.4
Disclosed:
Feb 21, 2023

Redirect Redirection <= 1.1.3 - Missing Authorization in 'SaveSettings' function

medium

The Redirect Redirection plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the SaveSettings function called via an AJAX action in versions up to, and including, 1.1.3. This makes it possible for authenticated attackers with subscriber-level access, and above, t...

CVSS:
4.3
Affected:
up to 1.1.3
Fixed in:
1.1.4
Disclosed:
Feb 21, 2023

Redirect Redirection <= 1.1.3 - Cross-Site Request Forgery via 'bulkDelete' function

medium

The Redirect Redirection plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3. This is due to missing or incorrect nonce validation on the bulkDelete function. This makes it possible for unauthenticated attackers to delete redirect rules in bulk, via a forged request...

CVSS:
4.3
Affected:
up to 1.1.3
Fixed in:
1.1.4
Disclosed:
Feb 21, 2023

Redirect Redirection <= 1.1.3 - Missing Authorization in 'selectAll' function

medium

The Redirect Redirection plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the selectAll function in versions up to, and including, 1.1.3. This makes it possible for authenticated attackers with subscriber-level access, and above, to retrieve specific redirects.

CVSS:
4.3
Affected:
up to 1.1.3
Fixed in:
1.1.4
Disclosed:
Feb 21, 2023

Redirect Redirection <= 1.1.3 - Missing Authorization in 'instantEditRedirect' function

medium

The Redirect Redirection plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the instantEditRedirect function called via an AJAX action in versions up to, and including, 1.1.3. This makes it possible for authenticated attackers with subscriber-level access, and a...

CVSS:
4.3
Affected:
up to 1.1.3
Fixed in:
1.1.4
Disclosed:
Feb 21, 2023

Redirect Redirection <= 1.1.3 - Cross-Site Request Forgery via 'addRedirectRule' function

medium

The Redirect Redirection plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3. This is due to missing or incorrect nonce validation on the addRedirectRule function. This makes it possible for unauthenticated attackers to add redirect rules, via a forged request grante...

CVSS:
4.3
Affected:
up to 1.1.3
Fixed in:
1.1.4
Disclosed:
Feb 21, 2023

Redirect Redirection <= 1.1.3 - Cross-Site Request Forgery via 'saveRedirectSettings' function

medium

The Redirect Redirection plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3. This is due to missing or incorrect nonce validation on the saveRedirectSettings function. This makes it possible for unauthenticated attackers to modify redirect settings, via a forged req...

CVSS:
4.3
Affected:
up to 1.1.3
Fixed in:
1.1.4
Disclosed:
Feb 21, 2023

Redirect Redirection <= 1.1.3 - Missing Authorization in 'liveSearch' function

medium

The Redirect Redirection plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the liveSearch function called via an AJAX action in versions up to, and including, 1.1.3. This makes it possible for authenticated attackers with subscriber-level access, and above, to search...

CVSS:
4.3
Affected:
up to 1.1.3
Fixed in:
1.1.4
Disclosed:
Feb 21, 2023

Redirect Redirection <= 1.1.3 - Missing Authorization in 'loadSettings' function

medium

The Redirect Redirection plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the loadSettings function in versions up to, and including, 1.1.3. This makes it possible for authenticated attackers with subscriber-level access, and above, to load the plugin's settings.

CVSS:
4.3
Affected:
up to 1.1.3
Fixed in:
1.1.4
Disclosed:
Feb 21, 2023

Redirect Redirection <= 1.1.3 - Missing Authorization in 'addRedirectRule' function

medium

The Redirect Redirection plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the addRedirectRule function called via an AJAX action in versions up to, and including, 1.1.3. This makes it possible for authenticated attackers with subscriber-level access, and above...

CVSS:
4.3
Affected:
up to 1.1.3
Fixed in:
1.1.4
Disclosed:
Feb 21, 2023

Redirect Redirection <= 1.1.3 - Missing Authorization in 'logFilter' function

medium

The Redirect Redirection plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the logFilter function in versions up to, and including, 1.1.3. This makes it possible for authenticated attackers with subscriber-level access, and above, to filter and view logs.

CVSS:
4.3
Affected:
up to 1.1.3
Fixed in:
1.1.4
Disclosed:
Feb 21, 2023

Redirect Redirection <= 1.1.3 - Cross-Site Request Forgery via 'deleteRedirect' function

medium

The Redirect Redirection plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3. This is due to missing or incorrect nonce validation on the deleteRedirect function. This makes it possible for unauthenticated attackers to delete redirects, via a forged request granted t...

CVSS:
4.3
Affected:
up to 1.1.3
Fixed in:
1.1.4
Disclosed:
Feb 21, 2023

Redirect Redirection <= 1.1.3 - Cross-Site Request Forgery via 'cronLogDeleteOption' function

medium

The Redirect Redirection plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3. This is due to missing or incorrect nonce validation on the cronLogDeleteOption function. This makes it possible for unauthenticated attackers to delete cronLog options, via a forged reques...

CVSS:
4.3
Affected:
up to 1.1.3
Fixed in:
1.1.4
Disclosed:
Feb 21, 2023

Redirection [redirect-redirection] < 1.1.4

unknown

The Redirect Redirection plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3. This is due to missing or incorrect nonce validation on the bulkDelete function. This makes it possible for unauthenticated attackers to delete redirect rules in bulk, via a forged request...

Affected:
up to 1.1.4
Fixed in:
1.1.4
Disclosed:
Feb 21, 2023

Redirection [redirect-redirection] < 1.1.4

unknown

The Redirect Redirection plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3. This is due to missing or incorrect nonce validation on the instantEditRedirect function. This makes it possible for unauthenticated attackers to edit redirects via a forged request granted...

Affected:
up to 1.1.4
Fixed in:
1.1.4
Disclosed:
Feb 21, 2023

Redirection [redirect-redirection] < 1.1.4

unknown

The Redirect Redirection plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3. This is due to missing or incorrect nonce validation on the deleteRedirect function. This makes it possible for unauthenticated attackers to delete redirects, via a forged request granted t...

Affected:
up to 1.1.4
Fixed in:
1.1.4
Disclosed:
Feb 21, 2023

Redirection [redirect-redirection] < 1.1.4

unknown

The Redirect Redirection plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3. This is due to missing or incorrect nonce validation on the cronLogDeleteOption function. This makes it possible for unauthenticated attackers to delete cronLog options, via a forged reques...

Affected:
up to 1.1.4
Fixed in:
1.1.4
Disclosed:
Feb 21, 2023

Redirection [redirect-redirection] < 1.1.4

unknown

The Redirect Redirection plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3. This is due to missing or incorrect nonce validation on the statusBulkEdit function. This makes it possible for unauthenticated attackers to bulk edit redirect rules, via a forged request g...

Affected:
up to 1.1.4
Fixed in:
1.1.4
Disclosed:
Feb 21, 2023

Redirection [redirect-redirection] < 1.1.4

unknown

The Redirect Redirection plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3. This is due to missing or incorrect nonce validation on the addRedirectRule function. This makes it possible for unauthenticated attackers to add redirect rules, via a forged request grante...

Affected:
up to 1.1.4
Fixed in:
1.1.4
Disclosed:
Feb 21, 2023

Redirection [redirect-redirection] < 1.1.4

unknown

The Redirect Redirection plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the saveRedirectSettings function called via an AJAX action in versions up to, and including, 1.1.3. This makes it possible for authenticated attackers with subscriber-level access, and...

Affected:
up to 1.1.4
Fixed in:
1.1.4
Disclosed:
Feb 21, 2023

Redirection [redirect-redirection] < 1.1.4

unknown

The Redirect Redirection plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the SaveSettings function called via an AJAX action in versions up to, and including, 1.1.3. This makes it possible for authenticated attackers with subscriber-level access, and above, t...

Affected:
up to 1.1.4
Fixed in:
1.1.4
Disclosed:
Feb 21, 2023

Redirection [redirect-redirection] < 1.1.4

unknown

The Redirect Redirection plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the logFilter function in versions up to, and including, 1.1.3. This makes it possible for authenticated attackers with subscriber-level access, and above, to filter and view logs.

Affected:
up to 1.1.4
Fixed in:
1.1.4
Disclosed:
Feb 21, 2023

Redirection [redirect-redirection] < 1.1.4

unknown

The Redirect Redirection plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the logPageContent function called via an AJAX action in versions up to, and including, 1.1.3. This makes it possible for authenticated attackers with subscriber-level access, and above, to vi...

Affected:
up to 1.1.4
Fixed in:
1.1.4
Disclosed:
Feb 21, 2023

Redirection [redirect-redirection] < 1.1.4

unknown

The Redirect Redirection plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the selectAll function in versions up to, and including, 1.1.3. This makes it possible for authenticated attackers with subscriber-level access, and above, to retrieve specific redirects.

Affected:
up to 1.1.4
Fixed in:
1.1.4
Disclosed:
Feb 21, 2023

Redirection [redirect-redirection] < 1.1.4

unknown

The Redirect Redirection plugin for WordPress is vulnerable to unauthorized modification of settings due to a missing capability check on the deleteRedirect function called via an AJAX action in versions up to, and including, 1.1.3. This makes it possible for authenticated attackers with subscriber-level access, and ab...

Affected:
up to 1.1.4
Fixed in:
1.1.4
Disclosed:
Feb 21, 2023

Redirection [redirect-redirection] < 1.1.4

unknown

The Redirect Redirection plugin for WordPress is vulnerable to unauthorized disclosure of data due to a missing capability check on the loadRedirectSettings function called via an AJAX action in versions up to, and including, 1.1.3. This makes it possible for authenticated attackers with subscriber-level access, and ab...

Affected:
up to 1.1.4
Fixed in:
1.1.4
Disclosed:
Feb 21, 2023

Redirection [redirect-redirection] < 1.1.4

unknown

The Redirect Redirection plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the instantEditRedirect function called via an AJAX action in versions up to, and including, 1.1.3. This makes it possible for authenticated attackers with subscriber-level access, and a...

Affected:
up to 1.1.4
Fixed in:
1.1.4
Disclosed:
Feb 21, 2023

Redirection [redirect-redirection] < 1.1.4

unknown

The Redirect Redirection plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the addRedirectRule function called via an AJAX action in versions up to, and including, 1.1.3. This makes it possible for authenticated attackers with subscriber-level access, and above...

Affected:
up to 1.1.4
Fixed in:
1.1.4
Disclosed:
Feb 21, 2023

Redirection [redirect-redirection] < 1.1.4

unknown

The Redirect Redirection plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the bulkDelete function called via an AJAX action in versions up to, and including, 1.1.3. This makes it possible for authenticated attackers with subscriber-level access, and above, to...

Affected:
up to 1.1.4
Fixed in:
1.1.4
Disclosed:
Feb 21, 2023

Redirection [redirect-redirection] < 1.1.4

unknown

The Redirect Redirection plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the addRedirect function called via an AJAX action in versions up to, and including, 1.1.3. This makes it possible for authenticated attackers with subscriber-level access, and above, to...

Affected:
up to 1.1.4
Fixed in:
1.1.4
Disclosed:
Feb 21, 2023

Redirection [redirect-redirection] < 1.1.4

unknown

The Redirect Redirection plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the liveSearch function called via an AJAX action in versions up to, and including, 1.1.3. This makes it possible for authenticated attackers with subscriber-level access, and above, to search...

Affected:
up to 1.1.4
Fixed in:
1.1.4
Disclosed:
Feb 21, 2023

Redirection [redirect-redirection] < 1.1.4

unknown

The Redirect Redirection plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the statusBulkEdit function called via an AJAX action in versions up to, and including, 1.1.3. This makes it possible for authenticated attackers with subscriber-level access, and above,...

Affected:
up to 1.1.4
Fixed in:
1.1.4
Disclosed:
Feb 21, 2023

Redirection [redirect-redirection] < 1.1.4

unknown

The Redirect Redirection plugin for WordPress is vulnerable to unauthorized disclosure of data due to a missing capability check on the redirectionPageContent function called via an AJAX action in versions up to, and including, 1.1.3. This makes it possible for authenticated attackers with subscriber-level access, and...

Affected:
up to 1.1.4
Fixed in:
1.1.4
Disclosed:
Feb 21, 2023

Redirection [redirect-redirection] < 1.1.4

unknown

The Redirect Redirection plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the loadSettings function in versions up to, and including, 1.1.3. This makes it possible for authenticated attackers with subscriber-level access, and above, to load the plugin's settings.

Affected:
up to 1.1.4
Fixed in:
1.1.4
Disclosed:
Feb 21, 2023

Redirection [redirect-redirection] < 1.1.4

unknown

The Redirect Redirection plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3. This is due to missing or incorrect nonce validation on the SaveSettings function. This makes it possible for unauthenticated attackers to update the plugin's settings, via a forged request...

Affected:
up to 1.1.4
Fixed in:
1.1.4
Disclosed:
Feb 21, 2023

Redirection [redirect-redirection] < 1.1.4

unknown

The Redirect Redirection plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3. This is due to missing or incorrect nonce validation on the saveRedirectSettings function. This makes it possible for unauthenticated attackers to modify redirect settings, via a forged req...

Affected:
up to 1.1.4
Fixed in:
1.1.4
Disclosed:
Feb 21, 2023

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database