plugin

Seo Redirection Vulnerabilities

28 known security issues reported for the Seo Redirection WordPress plugin. Most recent disclosed Aug 3, 2026.

4 high 7 medium

Running Seo Redirection on your site? Check whether your installed version is affected.

Scan your site free

SEO Redirection Plugin – 301 Redirect Manager <= 9.18 - Authenticated (Subscriber+) Information Exposure

medium

The SEO Redirection Plugin – 301 Redirect Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 9.18. This makes it possible for authenticated attackers, with Subscriber-level access and above, to extract redirect rule data.

CVSS:
4.3
Affected:
up to 9.18
Fixed in:
9.19
Disclosed:
Aug 3, 2026

CVE-2026-13703 on NVD →

SEO Redirection Plugin – 301 Redirect Manager <= 9.17 - Unauthenticated Stored Cross-Site Scripting

high

The SEO Redirection Plugin – 301 Redirect Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 9.17 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will e...

CVSS:
7.2
Affected:
up to 9.17
Fixed in:
9.18
Disclosed:
Jun 12, 2026

CVE-2026-52702 on NVD →

SEO Redirection Plugin &#8211; 301 Redirect Manager [seo-redirection] < 9.1

unknown

[en] Multiple Cross-Site Scripting (CSRF) vulnerabilities in SEO Redirection Plugin plugin <= 8.9 on WordPress.

Affected:
up to 9.1
Fixed in:
9.1
Disclosed:
Nov 18, 2022

CVE-2022-40695 on NVD →

SEO Redirection Plugin <= 8.9 - Cross-Site Request Forgery

high

The SEO Redirection Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 8.9. This is due to missing nonce validation in the option_page_history.php and option_page_404.php files. This makes it possible for unauthenticated attackers to change 404 page settings and ma...

CVSS:
8.8
Affected:
up to 8.9
Fixed in:
9.1
Disclosed:
Oct 25, 2022

CVE-2022-40695 on NVD →

SEO Redirection Plugin &#8211; 301 Redirect Manager [seo-redirection] < 9.1

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in SEO Redirection plugin <= 8.9 at WordPress, leading to deletion of 404 errors and redirection history.

Affected:
up to 9.1
Fixed in:
9.1
Disclosed:
Sep 23, 2022

CVE-2022-38704 on NVD →

SEO Redirection Plugin – 301 Redirect Manager <= 8.9 - Cross-Site Request Forgery

high

The SEO Redirection Plugin – 301 Redirect Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 8.9. This is due to missing nonce validation in the ~/options/option_page_404.php and ~/options/option_page_history.php files. This makes it possible for unauthenticated a...

CVSS:
8.8
Affected:
up to 8.9
Fixed in:
9.1
Disclosed:
Aug 1, 2022

CVE-2022-38704 on NVD →

SEO Redirection Plugin &#8211; 301 Redirect Manager [seo-redirection] < 9.1

unknown

[en] The importFromRedirection AJAX action of the SEO Redirection Plugin – 301 Redirect Manager WordPress plugin before 8.2, available to any authenticated user, does not properly sanitise the offset parameter before using it in a SQL statement, leading an SQL injection when the redirection plugin is also installed

Affected:
up to 9.1
Fixed in:
9.1
Disclosed:
Nov 17, 2021

CVE-2021-24847 on NVD →

SEO Redirection <= 8.1 - Subscriber+ SQL Injection

high

The importFromRedirection AJAX action of the SEO Redirection Plugin – 301 Redirect Manager WordPress plugin before 8.2, available to any authenticated user, does not properly sanitise the offset parameter before using it in a SQL statement, leading an SQL injection when the redirection plugin is also installed

CVSS:
8.8
Affected:
up to 8.1
Fixed in:
8.2
Disclosed:
Oct 18, 2021

CVE-2021-24847 on NVD →

SEO Redirection Plugin – 301 Redirect Manager <= 7.8 - Cross-Site Request Forgery

medium

The SEO Redirection Plugin – 301 Redirect Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 7.8. This is due to missing or incorrect nonce validation. This makes it possible for unauthenticated attackers to delete arbitrary redirects via a forged request granted...

CVSS:
6.5
Affected:
up to 7.8
Fixed in:
7.9
Disclosed:
Sep 15, 2021

SEO Redirection Plugin &#8211; 301 Redirect Manager [seo-redirection] < 7.9

unknown

The SEO Redirection Plugin – 301 Redirect Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 7.8. This is due to missing or incorrect nonce validation. This makes it possible for unauthenticated attackers to delete arbitrary redirects via a forged request granted...

Affected:
up to 7.9
Fixed in:
7.9
Disclosed:
Sep 15, 2021

SEO Redirection Plugin – 301 Redirect Manager <= 7.3 - Reflected Cross-Site Scripting

medium

The SEO Redirection plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘tab’ parameter in versions up to, and including, 7.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if...

CVSS:
6.1
Affected:
up to 7.3
Fixed in:
7.4
Disclosed:
Sep 13, 2021

SEO Redirection Plugin &#8211; 301 Redirect Manager [seo-redirection] < 7.4

unknown

The SEO Redirection plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘tab’ parameter in versions up to, and including, 7.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if...

Affected:
up to 7.4
Fixed in:
7.4
Disclosed:
Sep 13, 2021

SEO Redirection Plugin &#8211; 301 Redirect Manager [seo-redirection] < 7.1

unknown

[en] The SEO Redirection Plugin – 301 Redirect Manager WordPress plugin before 6.4 did not sanitise the Redirect From and Redirect To fields when creating a new redirect in the dashboard, allowing high privilege users (even with the unfiltered_html disabled) to set XSS payloads

Affected:
up to 7.1
Fixed in:
7.1
Disclosed:
May 17, 2021

CVE-2021-24327 on NVD →

SEO Redirection Plugin &#8211; 301 Redirect Manager [seo-redirection] < 6.4

unknown

Authenticated Persistent Cross-Site Scripting (XSS) vulnerability discovered by m0ze (Patchstack Red Team) in WordPress SEO Redirection plugin (versions <= 6.3)

Affected:
up to 6.4
Fixed in:
6.4
Disclosed:
Apr 21, 2021

SEO Redirection Plugin &#8211; 301 Redirect Manager [seo-redirection] < 6.4

unknown

Authenticated Reflected Cross-Site Scripting (XSS) vulnerability discovered by m0ze (Patchstack Red Team) in WordPress SEO Redirection plugin (versions <= 6.3).

Affected:
up to 6.4
Fixed in:
6.4
Disclosed:
Apr 21, 2021

SEO Redirection <= 6.4 - Authenticated Stored Cross-Site Scripting

medium

The SEO Redirection Plugin – 301 Redirect Manager WordPress plugin before 7.1 did not sanitise the Redirect From and Redirect To fields when creating a new redirect in the dashboard, allowing high privilege users (even with the unfiltered_html disabled) to set XSS payloads

CVSS:
4.8
Affected:
up to 6.4
Fixed in:
7.1
Disclosed:
Apr 16, 2021

CVE-2021-24327 on NVD →

SEO Redirection Plugin &#8211; 301 Redirect Manager [seo-redirection] < 6.4

unknown

[en] The setting page of the SEO Redirection Plugin - 301 Redirect Manager WordPress plugin before 6.4 is vulnerable to reflected Cross-Site Scripting (XSS) as user input is not properly sanitised before being output in an attribute.

Affected:
up to 6.4
Fixed in:
6.4
Disclosed:
Apr 5, 2021

CVE-2021-24187 on NVD →

SEO Redirection Plugin - 301 Redirect Manager <= 6.3 - Reflected Cross-Site Scripting

medium

The setting page of the SEO Redirection Plugin - 301 Redirect Manager WordPress plugin before 6.4 is vulnerable to reflected Cross-Site Scripting (XSS) as user input is not properly sanitised before being output in an attribute.

CVSS:
6.1
Affected:
up to 6.3
Fixed in:
6.4
Disclosed:
Mar 16, 2021

CVE-2021-24187 on NVD →

SEO Redirection Plugin &#8211; 301 Redirect Manager [seo-redirection] < 4.3

unknown

[en] The seo-redirection plugin before 4.3 for WordPress has stored XSS.

Affected:
up to 4.3
Fixed in:
4.3
Disclosed:
Aug 21, 2019

CVE-2016-10896 on NVD →

SEO Redirection <= 4.2 - Stored Cross-Site Scripting

medium

The SEO Redirection plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an unknown parameter in versions up to, and including, 4.2 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts in pages that will execute whenever a user...

CVSS:
6.1
Affected:
up to 4.3
Fixed in:
4.3
Disclosed:
Aug 25, 2015

CVE-2016-10896 on NVD →

SEO Redirection <= 2.8 - Reflected Cross-Site Scripting

medium

The SEO Redirection Plugin – 301 Redirect Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘search’ parameter in versions before 2.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pag...

CVSS:
6.1
Affected:
up to 2.9
Fixed in:
2.9
Disclosed:
Aug 21, 2015

SEO Redirection Plugin &#8211; 301 Redirect Manager [seo-redirection] < 2.9

unknown

Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Update the plugin.

Affected:
up to 2.9
Fixed in:
2.9
Disclosed:
Aug 21, 2015

SEO Redirection Plugin &#8211; 301 Redirect Manager [seo-redirection] < 2.9

unknown

The SEO Redirection Plugin – 301 Redirect Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘search’ parameter in versions before 2.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pag...

Affected:
up to 2.9
Fixed in:
2.9
Disclosed:
Aug 21, 2015

SEO Redirection Plugin &#8211; 301 Redirect Manager [seo-redirection] < 2.3

unknown

Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Update the plugin.

Affected:
up to 2.3
Fixed in:
2.3
Disclosed:
Dec 15, 2014

SEO Redirection Plugin &#8211; 301 Redirect Manager [seo-redirection] < 2.9

unknown

The plugin was affected by an Authenticated Reflected Cross-Site Scripting (XSS) security vulnerability in its settings page, via the search GET parameter

Affected:
up to 2.9
Fixed in:
2.9

SEO Redirection Plugin &#8211; 301 Redirect Manager [seo-redirection] < 2.3

unknown

The plugin did not sanitise the referer link from requests before displaying them in the &#039;Settings &gt; SEO Redirection &gt; Redirection History&#039; page. This result in a Store dCross-Site Scripting (XSS) issue

Affected:
up to 2.3
Fixed in:
2.3

SEO Redirection Plugin &#8211; 301 Redirect Manager [seo-redirection] < 7.9

unknown

The plugin does have CSRF in place, allowing attackers to make logged in admin delete arbitrary Custom and Post Redirects via a CSRF attack.

Affected:
up to 7.9
Fixed in:
7.9

SEO Redirection Plugin &#8211; 301 Redirect Manager [seo-redirection] < 7.4

unknown

The plugin does not escape the tab parameter before outputting it back in JavaScript code, leading to a Reflected Cross-Site Scripting issue

Affected:
up to 7.4
Fixed in:
7.4

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database