Redirection [redirect-redirection] < 1.1.4
unknown
[en] Missing Authorization vulnerability in social share pro Social Share Icons & Social Share Buttons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Social Share Icons & Social Share Buttons: from n/a through 3.5.7.
- Affected:
- up to 1.1.4
- Fixed in:
- 1.1.4
- Disclosed:
- Dec 13, 2024
CVE-2023-38514 on NVD →
Inisev Analyst Module <= Various Versions - Missing Authorization
medium
Multiple plugins and/or themes by Inisev for WordPress are vulnerable to unauthorized access due to a missing capability check on several functions in various versions. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform unauthorized actions.
- CVSS:
- 4.3
- Affected:
- up to 1.1.9
- Fixed in:
- 1.2.0
- Disclosed:
- Apr 10, 2024
CVE-2024-31435 on NVD →
Redirection [redirect-redirection] < 1.1.4
unknown
[en] Several plugins for WordPress by Inisev are vulnerable to unauthorized installation of plugins due to a missing capability check on the handle_installation function that is called via the inisev_installation AJAX aciton in various versions. This makes it possible for authenticated attackers with minimal permission...
- Affected:
- up to 1.1.4
- Fixed in:
- 1.1.4
- Disclosed:
- Jul 28, 2023
CVE-2023-0958 on NVD →
Redirection [redirect-redirection] < 1.1.4
unknown
[en] Several plugins for WordPress by Inisev are vulnerable to Cross-Site Request Forgery to unauthorized installation of plugins due to a missing nonce check on the handle_installation function that is called via the inisev_installation AJAX aciton in various versions. This makes it possible for unauthenticated attack...
- Affected:
- up to 1.1.4
- Fixed in:
- 1.1.4
- Disclosed:
- Jul 28, 2023
CVE-2023-3977 on NVD →
Inisev Plugins (Various Versions) - Missing Authorization on handle_installation function
medium
Several plugins for WordPress by Inisev are vulnerable to unauthorized installation of plugins due to a missing capability check on the handle_installation function that is called via the inisev_installation AJAX aciton in various versions. This makes it possible for authenticated attackers with minimal permissions, su...
- CVSS:
- 4.3
- Affected:
- up to 1.1.3
- Fixed in:
- 1.1.4
- Disclosed:
- Jul 27, 2023
CVE-2023-0958 on NVD →
Inisev Plugins (Various Versions) - Cross-Site Request Forgery on handle_installation function
medium
Several plugins for WordPress by Inisev are vulnerable to Cross-Site Request Forgery to unauthorized installation of plugins due to a missing nonce check on the handle_installation function that is called via the inisev_installation AJAX aciton in various versions. This makes it possible for unauthenticated attackers t...
- CVSS:
- 4.3
- Affected:
- up to 1.1.3
- Fixed in:
- 1.1.4
- Disclosed:
- Jul 27, 2023
CVE-2023-3977 on NVD →
Redirection [redirect-redirection] < 1.1.5
unknown
[en] The Redirection WordPress plugin before 1.1.5 does not have CSRF checks in the uninstall action, which could allow attackers to make logged in admins delete all the redirections through a CSRF attack.
- Affected:
- up to 1.1.5
- Fixed in:
- 1.1.5
- Disclosed:
- Apr 17, 2023
CVE-2023-1331 on NVD →
Redirection [redirect-redirection] < 1.1.5
unknown
[en] The Redirection WordPress plugin before 1.1.4 does not add nonce verification in place when adding the redirect, which could allow attackers to add redirects via a CSRF attack.
- Affected:
- up to 1.1.5
- Fixed in:
- 1.1.5
- Disclosed:
- Apr 3, 2023
CVE-2023-1330 on NVD →
Redirection <= 1.1.4 - Cross-Site Request Forgery to Plugin Reset
medium
The Redirection plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.4. This is due to missing or incorrect nonce validation on the 'uninstall' function hooked via admin_post. This makes it possible for unauthenticated attackers to deactivate and reset the plugin via a...
- CVSS:
- 5.4
- Affected:
- up to 1.1.4
- Fixed in:
- 1.1.5
- Disclosed:
- Mar 21, 2023
CVE-2023-1331 on NVD →
Redirection [redirect-redirection] < 1.1.5
unknown
Update the WordPress Redirect Redirection plugin to the latest available version (at least 1.1.5).
Unknown discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress Redirect Redirection Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted action...
- Affected:
- up to 1.1.5
- Fixed in:
- 1.1.5
- Disclosed:
- Mar 15, 2023
Redirect Redirection <= 1.1.4 - Cross-Site Request Forgery to Plugin De-Installation
medium
The Redirect Redirection plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.4. This is due to missing nonce validation on the uninstall() function called via an admin_post hook. This makes it possible for unauthenticated attackers to uninstall the plugin via a forged...
- CVSS:
- 5.4
- Affected:
- up to 1.1.4
- Fixed in:
- 1.1.5
- Disclosed:
- Mar 14, 2023
Redirection [redirect-redirection] < 1.1.5
unknown
The Redirect Redirection plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.4. This is due to missing nonce validation on the uninstall() function called via an admin_post hook. This makes it possible for unauthenticated attackers to uninstall the plugin via a forged...
- Affected:
- up to 1.1.5
- Fixed in:
- 1.1.5
- Disclosed:
- Mar 14, 2023
Redirect Redirection <= 1.1.3 - Missing Authorization in 'LoadTab' function
medium
The Redirect Redirection plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the LoadTab function called via an AJAX action in versions up to, and including, 1.1.3. This makes it possible for authenticated attackers with subscriber-level access, and above, to load tabs...
- CVSS:
- 4.3
- Affected:
- up to 1.1.3
- Fixed in:
- 1.1.4
- Disclosed:
- Feb 22, 2023
Redirect Redirection <= 1.1.3 - Cross-Site Request Forgery via 'addRedirect' function
medium
The Redirect Redirection plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3. This is due to missing or incorrect nonce validation on the addRedirect function. This makes it possible for unauthenticated attackers to add redirects, via a forged request granted they ca...
- CVSS:
- 4.3
- Affected:
- up to 1.1.3
- Fixed in:
- 1.1.4
- Disclosed:
- Feb 22, 2023
CVE-2023-1330 on NVD →
Redirection [redirect-redirection] < 1.1.4
unknown
The Redirect Redirection plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the LoadTab function called via an AJAX action in versions up to, and including, 1.1.3. This makes it possible for authenticated attackers with subscriber-level access, and above, to load tabs...
- Affected:
- up to 1.1.4
- Fixed in:
- 1.1.4
- Disclosed:
- Feb 22, 2023
Redirection [redirect-redirection] < 1.1.4
unknown
Update the WordPress Redirect Redirection plugin to the latest available version (at least 1.1.4).
WordFence discovered and reported this Broken Access Control vulnerability in WordPress Redirect Redirection Plugin. This vulnerability has been fixed in version 1.1.4.
- Affected:
- up to 1.1.4
- Fixed in:
- 1.1.4
- Disclosed:
- Feb 22, 2023
Redirection [redirect-redirection] < 1.1.4
unknown
The Redirect Redirection plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3. This is due to missing or incorrect nonce validation on the addRedirect function. This makes it possible for unauthenticated attackers to add redirects, via a forged request granted they ca...
- Affected:
- up to 1.1.4
- Fixed in:
- 1.1.4
- Disclosed:
- Feb 22, 2023
Redirect Redirection <= 1.1.3 - Missing Authorization in 'loadRedirectSettings' function
medium
The Redirect Redirection plugin for WordPress is vulnerable to unauthorized disclosure of data due to a missing capability check on the loadRedirectSettings function called via an AJAX action in versions up to, and including, 1.1.3. This makes it possible for authenticated attackers with subscriber-level access, and ab...
- CVSS:
- 5.3
- Affected:
- up to 1.1.3
- Fixed in:
- 1.1.4
- Disclosed:
- Feb 21, 2023
Redirect Redirection <= 1.1.3 - Missing Authorization in 'logPageContent' function
medium
The Redirect Redirection plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the logPageContent function called via an AJAX action in versions up to, and including, 1.1.3. This makes it possible for authenticated attackers with subscriber-level access, and above, to vi...
- CVSS:
- 4.3
- Affected:
- up to 1.1.3
- Fixed in:
- 1.1.4
- Disclosed:
- Feb 21, 2023
Redirect Redirection <= 1.1.3 - Missing Authorization in 'bulkDelete' function
medium
The Redirect Redirection plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the bulkDelete function called via an AJAX action in versions up to, and including, 1.1.3. This makes it possible for authenticated attackers with subscriber-level access, and above, to...
- CVSS:
- 4.3
- Affected:
- up to 1.1.3
- Fixed in:
- 1.1.4
- Disclosed:
- Feb 21, 2023
Redirect Redirection <= 1.1.3 - Missing Authorization in 'statusBulkEdit' function
medium
The Redirect Redirection plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the statusBulkEdit function called via an AJAX action in versions up to, and including, 1.1.3. This makes it possible for authenticated attackers with subscriber-level access, and above,...
- CVSS:
- 4.3
- Affected:
- up to 1.1.3
- Fixed in:
- 1.1.4
- Disclosed:
- Feb 21, 2023
Redirect Redirection <= 1.1.3 - Missing Authorization in 'saveRedirectSettings' function
medium
The Redirect Redirection plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the saveRedirectSettings function called via an AJAX action in versions up to, and including, 1.1.3. This makes it possible for authenticated attackers with subscriber-level access, and...
- CVSS:
- 4.3
- Affected:
- up to 1.1.3
- Fixed in:
- 1.1.4
- Disclosed:
- Feb 21, 2023
Redirect Redirection <= 1.1.3 - Cross-Site Request Forgery via 'instantEditRedirect' function
medium
The Redirect Redirection plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3. This is due to missing or incorrect nonce validation on the instantEditRedirect function. This makes it possible for unauthenticated attackers to edit redirects via a forged request granted...
- CVSS:
- 4.3
- Affected:
- up to 1.1.3
- Fixed in:
- 1.1.4
- Disclosed:
- Feb 21, 2023
Redirect Redirection <= 1.1.3 - Missing Authorization in 'redirectionPageContent' function
medium
The Redirect Redirection plugin for WordPress is vulnerable to unauthorized disclosure of data due to a missing capability check on the redirectionPageContent function called via an AJAX action in versions up to, and including, 1.1.3. This makes it possible for authenticated attackers with subscriber-level access, and...
- CVSS:
- 4.3
- Affected:
- up to 1.1.3
- Fixed in:
- 1.1.4
- Disclosed:
- Feb 21, 2023
Redirect Redirection <= 1.1.3 - Cross-Site Request Forgery via 'statusBulkEdit' function
medium
The Redirect Redirection plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3. This is due to missing or incorrect nonce validation on the statusBulkEdit function. This makes it possible for unauthenticated attackers to bulk edit redirect rules, via a forged request g...
- CVSS:
- 4.3
- Affected:
- up to 1.1.3
- Fixed in:
- 1.1.4
- Disclosed:
- Feb 21, 2023
Redirect Redirection <= 1.1.3 - Missing Authorization in 'addRedirect' function
medium
The Redirect Redirection plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the addRedirect function called via an AJAX action in versions up to, and including, 1.1.3. This makes it possible for authenticated attackers with subscriber-level access, and above, to...
- CVSS:
- 4.3
- Affected:
- up to 1.1.3
- Fixed in:
- 1.1.4
- Disclosed:
- Feb 21, 2023
Redirect Redirection <= 1.1.3 - Missing Authorization in 'deleteRedirect' function
medium
The Redirect Redirection plugin for WordPress is vulnerable to unauthorized modification of settings due to a missing capability check on the deleteRedirect function called via an AJAX action in versions up to, and including, 1.1.3. This makes it possible for authenticated attackers with subscriber-level access, and ab...
- CVSS:
- 4.3
- Affected:
- up to 1.1.3
- Fixed in:
- 1.1.4
- Disclosed:
- Feb 21, 2023
Redirect Redirection <= 1.1.3 - Cross-Site Request Forgery via 'SaveSettings' function
medium
The Redirect Redirection plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3. This is due to missing or incorrect nonce validation on the SaveSettings function. This makes it possible for unauthenticated attackers to update the plugin's settings, via a forged request...
- CVSS:
- 4.3
- Affected:
- up to 1.1.3
- Fixed in:
- 1.1.4
- Disclosed:
- Feb 21, 2023
Redirect Redirection <= 1.1.3 - Missing Authorization in 'SaveSettings' function
medium
The Redirect Redirection plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the SaveSettings function called via an AJAX action in versions up to, and including, 1.1.3. This makes it possible for authenticated attackers with subscriber-level access, and above, t...
- CVSS:
- 4.3
- Affected:
- up to 1.1.3
- Fixed in:
- 1.1.4
- Disclosed:
- Feb 21, 2023
Redirect Redirection <= 1.1.3 - Cross-Site Request Forgery via 'bulkDelete' function
medium
The Redirect Redirection plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3. This is due to missing or incorrect nonce validation on the bulkDelete function. This makes it possible for unauthenticated attackers to delete redirect rules in bulk, via a forged request...
- CVSS:
- 4.3
- Affected:
- up to 1.1.3
- Fixed in:
- 1.1.4
- Disclosed:
- Feb 21, 2023
Redirect Redirection <= 1.1.3 - Missing Authorization in 'selectAll' function
medium
The Redirect Redirection plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the selectAll function in versions up to, and including, 1.1.3. This makes it possible for authenticated attackers with subscriber-level access, and above, to retrieve specific redirects.
- CVSS:
- 4.3
- Affected:
- up to 1.1.3
- Fixed in:
- 1.1.4
- Disclosed:
- Feb 21, 2023
Redirect Redirection <= 1.1.3 - Missing Authorization in 'instantEditRedirect' function
medium
The Redirect Redirection plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the instantEditRedirect function called via an AJAX action in versions up to, and including, 1.1.3. This makes it possible for authenticated attackers with subscriber-level access, and a...
- CVSS:
- 4.3
- Affected:
- up to 1.1.3
- Fixed in:
- 1.1.4
- Disclosed:
- Feb 21, 2023
Redirect Redirection <= 1.1.3 - Cross-Site Request Forgery via 'addRedirectRule' function
medium
The Redirect Redirection plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3. This is due to missing or incorrect nonce validation on the addRedirectRule function. This makes it possible for unauthenticated attackers to add redirect rules, via a forged request grante...
- CVSS:
- 4.3
- Affected:
- up to 1.1.3
- Fixed in:
- 1.1.4
- Disclosed:
- Feb 21, 2023
Redirect Redirection <= 1.1.3 - Cross-Site Request Forgery via 'saveRedirectSettings' function
medium
The Redirect Redirection plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3. This is due to missing or incorrect nonce validation on the saveRedirectSettings function. This makes it possible for unauthenticated attackers to modify redirect settings, via a forged req...
- CVSS:
- 4.3
- Affected:
- up to 1.1.3
- Fixed in:
- 1.1.4
- Disclosed:
- Feb 21, 2023
Redirect Redirection <= 1.1.3 - Missing Authorization in 'liveSearch' function
medium
The Redirect Redirection plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the liveSearch function called via an AJAX action in versions up to, and including, 1.1.3. This makes it possible for authenticated attackers with subscriber-level access, and above, to search...
- CVSS:
- 4.3
- Affected:
- up to 1.1.3
- Fixed in:
- 1.1.4
- Disclosed:
- Feb 21, 2023
Redirect Redirection <= 1.1.3 - Missing Authorization in 'loadSettings' function
medium
The Redirect Redirection plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the loadSettings function in versions up to, and including, 1.1.3. This makes it possible for authenticated attackers with subscriber-level access, and above, to load the plugin's settings.
- CVSS:
- 4.3
- Affected:
- up to 1.1.3
- Fixed in:
- 1.1.4
- Disclosed:
- Feb 21, 2023
Redirect Redirection <= 1.1.3 - Missing Authorization in 'addRedirectRule' function
medium
The Redirect Redirection plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the addRedirectRule function called via an AJAX action in versions up to, and including, 1.1.3. This makes it possible for authenticated attackers with subscriber-level access, and above...
- CVSS:
- 4.3
- Affected:
- up to 1.1.3
- Fixed in:
- 1.1.4
- Disclosed:
- Feb 21, 2023
Redirect Redirection <= 1.1.3 - Missing Authorization in 'logFilter' function
medium
The Redirect Redirection plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the logFilter function in versions up to, and including, 1.1.3. This makes it possible for authenticated attackers with subscriber-level access, and above, to filter and view logs.
- CVSS:
- 4.3
- Affected:
- up to 1.1.3
- Fixed in:
- 1.1.4
- Disclosed:
- Feb 21, 2023
Redirect Redirection <= 1.1.3 - Cross-Site Request Forgery via 'deleteRedirect' function
medium
The Redirect Redirection plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3. This is due to missing or incorrect nonce validation on the deleteRedirect function. This makes it possible for unauthenticated attackers to delete redirects, via a forged request granted t...
- CVSS:
- 4.3
- Affected:
- up to 1.1.3
- Fixed in:
- 1.1.4
- Disclosed:
- Feb 21, 2023
Redirect Redirection <= 1.1.3 - Cross-Site Request Forgery via 'cronLogDeleteOption' function
medium
The Redirect Redirection plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3. This is due to missing or incorrect nonce validation on the cronLogDeleteOption function. This makes it possible for unauthenticated attackers to delete cronLog options, via a forged reques...
- CVSS:
- 4.3
- Affected:
- up to 1.1.3
- Fixed in:
- 1.1.4
- Disclosed:
- Feb 21, 2023
Redirection [redirect-redirection] < 1.1.4
unknown
The Redirect Redirection plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3. This is due to missing or incorrect nonce validation on the bulkDelete function. This makes it possible for unauthenticated attackers to delete redirect rules in bulk, via a forged request...
- Affected:
- up to 1.1.4
- Fixed in:
- 1.1.4
- Disclosed:
- Feb 21, 2023
Redirection [redirect-redirection] < 1.1.4
unknown
The Redirect Redirection plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3. This is due to missing or incorrect nonce validation on the instantEditRedirect function. This makes it possible for unauthenticated attackers to edit redirects via a forged request granted...
- Affected:
- up to 1.1.4
- Fixed in:
- 1.1.4
- Disclosed:
- Feb 21, 2023
Redirection [redirect-redirection] < 1.1.4
unknown
The Redirect Redirection plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3. This is due to missing or incorrect nonce validation on the deleteRedirect function. This makes it possible for unauthenticated attackers to delete redirects, via a forged request granted t...
- Affected:
- up to 1.1.4
- Fixed in:
- 1.1.4
- Disclosed:
- Feb 21, 2023
Redirection [redirect-redirection] < 1.1.4
unknown
The Redirect Redirection plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3. This is due to missing or incorrect nonce validation on the cronLogDeleteOption function. This makes it possible for unauthenticated attackers to delete cronLog options, via a forged reques...
- Affected:
- up to 1.1.4
- Fixed in:
- 1.1.4
- Disclosed:
- Feb 21, 2023
Redirection [redirect-redirection] < 1.1.4
unknown
The Redirect Redirection plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3. This is due to missing or incorrect nonce validation on the statusBulkEdit function. This makes it possible for unauthenticated attackers to bulk edit redirect rules, via a forged request g...
- Affected:
- up to 1.1.4
- Fixed in:
- 1.1.4
- Disclosed:
- Feb 21, 2023
Redirection [redirect-redirection] < 1.1.4
unknown
The Redirect Redirection plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3. This is due to missing or incorrect nonce validation on the addRedirectRule function. This makes it possible for unauthenticated attackers to add redirect rules, via a forged request grante...
- Affected:
- up to 1.1.4
- Fixed in:
- 1.1.4
- Disclosed:
- Feb 21, 2023
Redirection [redirect-redirection] < 1.1.4
unknown
The Redirect Redirection plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the saveRedirectSettings function called via an AJAX action in versions up to, and including, 1.1.3. This makes it possible for authenticated attackers with subscriber-level access, and...
- Affected:
- up to 1.1.4
- Fixed in:
- 1.1.4
- Disclosed:
- Feb 21, 2023
Redirection [redirect-redirection] < 1.1.4
unknown
The Redirect Redirection plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the SaveSettings function called via an AJAX action in versions up to, and including, 1.1.3. This makes it possible for authenticated attackers with subscriber-level access, and above, t...
- Affected:
- up to 1.1.4
- Fixed in:
- 1.1.4
- Disclosed:
- Feb 21, 2023
Redirection [redirect-redirection] < 1.1.4
unknown
The Redirect Redirection plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the logFilter function in versions up to, and including, 1.1.3. This makes it possible for authenticated attackers with subscriber-level access, and above, to filter and view logs.
- Affected:
- up to 1.1.4
- Fixed in:
- 1.1.4
- Disclosed:
- Feb 21, 2023
Redirection [redirect-redirection] < 1.1.4
unknown
The Redirect Redirection plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the logPageContent function called via an AJAX action in versions up to, and including, 1.1.3. This makes it possible for authenticated attackers with subscriber-level access, and above, to vi...
- Affected:
- up to 1.1.4
- Fixed in:
- 1.1.4
- Disclosed:
- Feb 21, 2023
Redirection [redirect-redirection] < 1.1.4
unknown
The Redirect Redirection plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the selectAll function in versions up to, and including, 1.1.3. This makes it possible for authenticated attackers with subscriber-level access, and above, to retrieve specific redirects.
- Affected:
- up to 1.1.4
- Fixed in:
- 1.1.4
- Disclosed:
- Feb 21, 2023
Redirection [redirect-redirection] < 1.1.4
unknown
The Redirect Redirection plugin for WordPress is vulnerable to unauthorized modification of settings due to a missing capability check on the deleteRedirect function called via an AJAX action in versions up to, and including, 1.1.3. This makes it possible for authenticated attackers with subscriber-level access, and ab...
- Affected:
- up to 1.1.4
- Fixed in:
- 1.1.4
- Disclosed:
- Feb 21, 2023
Redirection [redirect-redirection] < 1.1.4
unknown
The Redirect Redirection plugin for WordPress is vulnerable to unauthorized disclosure of data due to a missing capability check on the loadRedirectSettings function called via an AJAX action in versions up to, and including, 1.1.3. This makes it possible for authenticated attackers with subscriber-level access, and ab...
- Affected:
- up to 1.1.4
- Fixed in:
- 1.1.4
- Disclosed:
- Feb 21, 2023
Redirection [redirect-redirection] < 1.1.4
unknown
The Redirect Redirection plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the instantEditRedirect function called via an AJAX action in versions up to, and including, 1.1.3. This makes it possible for authenticated attackers with subscriber-level access, and a...
- Affected:
- up to 1.1.4
- Fixed in:
- 1.1.4
- Disclosed:
- Feb 21, 2023
Redirection [redirect-redirection] < 1.1.4
unknown
The Redirect Redirection plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the addRedirectRule function called via an AJAX action in versions up to, and including, 1.1.3. This makes it possible for authenticated attackers with subscriber-level access, and above...
- Affected:
- up to 1.1.4
- Fixed in:
- 1.1.4
- Disclosed:
- Feb 21, 2023
Redirection [redirect-redirection] < 1.1.4
unknown
The Redirect Redirection plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the bulkDelete function called via an AJAX action in versions up to, and including, 1.1.3. This makes it possible for authenticated attackers with subscriber-level access, and above, to...
- Affected:
- up to 1.1.4
- Fixed in:
- 1.1.4
- Disclosed:
- Feb 21, 2023
Redirection [redirect-redirection] < 1.1.4
unknown
The Redirect Redirection plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the addRedirect function called via an AJAX action in versions up to, and including, 1.1.3. This makes it possible for authenticated attackers with subscriber-level access, and above, to...
- Affected:
- up to 1.1.4
- Fixed in:
- 1.1.4
- Disclosed:
- Feb 21, 2023
Redirection [redirect-redirection] < 1.1.4
unknown
The Redirect Redirection plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the liveSearch function called via an AJAX action in versions up to, and including, 1.1.3. This makes it possible for authenticated attackers with subscriber-level access, and above, to search...
- Affected:
- up to 1.1.4
- Fixed in:
- 1.1.4
- Disclosed:
- Feb 21, 2023
Redirection [redirect-redirection] < 1.1.4
unknown
The Redirect Redirection plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the statusBulkEdit function called via an AJAX action in versions up to, and including, 1.1.3. This makes it possible for authenticated attackers with subscriber-level access, and above,...
- Affected:
- up to 1.1.4
- Fixed in:
- 1.1.4
- Disclosed:
- Feb 21, 2023
Redirection [redirect-redirection] < 1.1.4
unknown
The Redirect Redirection plugin for WordPress is vulnerable to unauthorized disclosure of data due to a missing capability check on the redirectionPageContent function called via an AJAX action in versions up to, and including, 1.1.3. This makes it possible for authenticated attackers with subscriber-level access, and...
- Affected:
- up to 1.1.4
- Fixed in:
- 1.1.4
- Disclosed:
- Feb 21, 2023
Redirection [redirect-redirection] < 1.1.4
unknown
The Redirect Redirection plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the loadSettings function in versions up to, and including, 1.1.3. This makes it possible for authenticated attackers with subscriber-level access, and above, to load the plugin's settings.
- Affected:
- up to 1.1.4
- Fixed in:
- 1.1.4
- Disclosed:
- Feb 21, 2023
Redirection [redirect-redirection] < 1.1.4
unknown
The Redirect Redirection plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3. This is due to missing or incorrect nonce validation on the SaveSettings function. This makes it possible for unauthenticated attackers to update the plugin's settings, via a forged request...
- Affected:
- up to 1.1.4
- Fixed in:
- 1.1.4
- Disclosed:
- Feb 21, 2023
Redirection [redirect-redirection] < 1.1.4
unknown
The Redirect Redirection plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3. This is due to missing or incorrect nonce validation on the saveRedirectSettings function. This makes it possible for unauthenticated attackers to modify redirect settings, via a forged req...
- Affected:
- up to 1.1.4
- Fixed in:
- 1.1.4
- Disclosed:
- Feb 21, 2023
Redirection [redirect-redirection] < 1.2.0
unknown
- Affected:
- up to 1.2.0
- Fixed in:
- 1.2.0
CVE-2024-31435 on NVD →