SEO Redirection Plugin – 301 Redirect Manager <= 9.18 - Authenticated (Subscriber+) Information Exposure
medium
The SEO Redirection Plugin – 301 Redirect Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 9.18. This makes it possible for authenticated attackers, with Subscriber-level access and above, to extract redirect rule data.
- CVSS:
- 4.3
- Affected:
- up to 9.18
- Fixed in:
- 9.19
- Disclosed:
- Aug 3, 2026
CVE-2026-13703 on NVD →
SEO Redirection Plugin – 301 Redirect Manager <= 9.17 - Unauthenticated Stored Cross-Site Scripting
high
The SEO Redirection Plugin – 301 Redirect Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 9.17 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will e...
- CVSS:
- 7.2
- Affected:
- up to 9.17
- Fixed in:
- 9.18
- Disclosed:
- Jun 12, 2026
CVE-2026-52702 on NVD →
SEO Redirection Plugin – 301 Redirect Manager [seo-redirection] < 9.1
unknown
[en] Multiple Cross-Site Scripting (CSRF) vulnerabilities in SEO Redirection Plugin plugin <= 8.9 on WordPress.
- Affected:
- up to 9.1
- Fixed in:
- 9.1
- Disclosed:
- Nov 18, 2022
CVE-2022-40695 on NVD →
SEO Redirection Plugin <= 8.9 - Cross-Site Request Forgery
high
The SEO Redirection Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 8.9. This is due to missing nonce validation in the option_page_history.php and option_page_404.php files. This makes it possible for unauthenticated attackers to change 404 page settings and ma...
- CVSS:
- 8.8
- Affected:
- up to 8.9
- Fixed in:
- 9.1
- Disclosed:
- Oct 25, 2022
CVE-2022-40695 on NVD →
SEO Redirection Plugin – 301 Redirect Manager [seo-redirection] < 9.1
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in SEO Redirection plugin <= 8.9 at WordPress, leading to deletion of 404 errors and redirection history.
- Affected:
- up to 9.1
- Fixed in:
- 9.1
- Disclosed:
- Sep 23, 2022
CVE-2022-38704 on NVD →
SEO Redirection Plugin – 301 Redirect Manager <= 8.9 - Cross-Site Request Forgery
high
The SEO Redirection Plugin – 301 Redirect Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 8.9. This is due to missing nonce validation in the ~/options/option_page_404.php and ~/options/option_page_history.php files. This makes it possible for unauthenticated a...
- CVSS:
- 8.8
- Affected:
- up to 8.9
- Fixed in:
- 9.1
- Disclosed:
- Aug 1, 2022
CVE-2022-38704 on NVD →
SEO Redirection Plugin – 301 Redirect Manager [seo-redirection] < 9.1
unknown
[en] The importFromRedirection AJAX action of the SEO Redirection Plugin – 301 Redirect Manager WordPress plugin before 8.2, available to any authenticated user, does not properly sanitise the offset parameter before using it in a SQL statement, leading an SQL injection when the redirection plugin is also installed
- Affected:
- up to 9.1
- Fixed in:
- 9.1
- Disclosed:
- Nov 17, 2021
CVE-2021-24847 on NVD →
SEO Redirection <= 8.1 - Subscriber+ SQL Injection
high
The importFromRedirection AJAX action of the SEO Redirection Plugin – 301 Redirect Manager WordPress plugin before 8.2, available to any authenticated user, does not properly sanitise the offset parameter before using it in a SQL statement, leading an SQL injection when the redirection plugin is also installed
- CVSS:
- 8.8
- Affected:
- up to 8.1
- Fixed in:
- 8.2
- Disclosed:
- Oct 18, 2021
CVE-2021-24847 on NVD →
SEO Redirection Plugin – 301 Redirect Manager <= 7.8 - Cross-Site Request Forgery
medium
The SEO Redirection Plugin – 301 Redirect Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 7.8. This is due to missing or incorrect nonce validation. This makes it possible for unauthenticated attackers to delete arbitrary redirects via a forged request granted...
- CVSS:
- 6.5
- Affected:
- up to 7.8
- Fixed in:
- 7.9
- Disclosed:
- Sep 15, 2021
SEO Redirection Plugin – 301 Redirect Manager [seo-redirection] < 7.9
unknown
The SEO Redirection Plugin – 301 Redirect Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 7.8. This is due to missing or incorrect nonce validation. This makes it possible for unauthenticated attackers to delete arbitrary redirects via a forged request granted...
- Affected:
- up to 7.9
- Fixed in:
- 7.9
- Disclosed:
- Sep 15, 2021
SEO Redirection Plugin – 301 Redirect Manager <= 7.3 - Reflected Cross-Site Scripting
medium
The SEO Redirection plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘tab’ parameter in versions up to, and including, 7.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if...
- CVSS:
- 6.1
- Affected:
- up to 7.3
- Fixed in:
- 7.4
- Disclosed:
- Sep 13, 2021
SEO Redirection Plugin – 301 Redirect Manager [seo-redirection] < 7.4
unknown
The SEO Redirection plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘tab’ parameter in versions up to, and including, 7.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if...
- Affected:
- up to 7.4
- Fixed in:
- 7.4
- Disclosed:
- Sep 13, 2021
SEO Redirection Plugin – 301 Redirect Manager [seo-redirection] < 7.1
unknown
[en] The SEO Redirection Plugin – 301 Redirect Manager WordPress plugin before 6.4 did not sanitise the Redirect From and Redirect To fields when creating a new redirect in the dashboard, allowing high privilege users (even with the unfiltered_html disabled) to set XSS payloads
- Affected:
- up to 7.1
- Fixed in:
- 7.1
- Disclosed:
- May 17, 2021
CVE-2021-24327 on NVD →
SEO Redirection Plugin – 301 Redirect Manager [seo-redirection] < 6.4
unknown
Authenticated Persistent Cross-Site Scripting (XSS) vulnerability discovered by m0ze (Patchstack Red Team) in WordPress SEO Redirection plugin (versions <= 6.3)
- Affected:
- up to 6.4
- Fixed in:
- 6.4
- Disclosed:
- Apr 21, 2021
SEO Redirection Plugin – 301 Redirect Manager [seo-redirection] < 6.4
unknown
Authenticated Reflected Cross-Site Scripting (XSS) vulnerability discovered by m0ze (Patchstack Red Team) in WordPress SEO Redirection plugin (versions <= 6.3).
- Affected:
- up to 6.4
- Fixed in:
- 6.4
- Disclosed:
- Apr 21, 2021
SEO Redirection <= 6.4 - Authenticated Stored Cross-Site Scripting
medium
The SEO Redirection Plugin – 301 Redirect Manager WordPress plugin before 7.1 did not sanitise the Redirect From and Redirect To fields when creating a new redirect in the dashboard, allowing high privilege users (even with the unfiltered_html disabled) to set XSS payloads
- CVSS:
- 4.8
- Affected:
- up to 6.4
- Fixed in:
- 7.1
- Disclosed:
- Apr 16, 2021
CVE-2021-24327 on NVD →
SEO Redirection Plugin – 301 Redirect Manager [seo-redirection] < 6.4
unknown
[en] The setting page of the SEO Redirection Plugin - 301 Redirect Manager WordPress plugin before 6.4 is vulnerable to reflected Cross-Site Scripting (XSS) as user input is not properly sanitised before being output in an attribute.
- Affected:
- up to 6.4
- Fixed in:
- 6.4
- Disclosed:
- Apr 5, 2021
CVE-2021-24187 on NVD →
SEO Redirection Plugin - 301 Redirect Manager <= 6.3 - Reflected Cross-Site Scripting
medium
The setting page of the SEO Redirection Plugin - 301 Redirect Manager WordPress plugin before 6.4 is vulnerable to reflected Cross-Site Scripting (XSS) as user input is not properly sanitised before being output in an attribute.
- CVSS:
- 6.1
- Affected:
- up to 6.3
- Fixed in:
- 6.4
- Disclosed:
- Mar 16, 2021
CVE-2021-24187 on NVD →
SEO Redirection Plugin – 301 Redirect Manager [seo-redirection] < 4.3
unknown
[en] The seo-redirection plugin before 4.3 for WordPress has stored XSS.
- Affected:
- up to 4.3
- Fixed in:
- 4.3
- Disclosed:
- Aug 21, 2019
CVE-2016-10896 on NVD →
SEO Redirection <= 4.2 - Stored Cross-Site Scripting
medium
The SEO Redirection plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an unknown parameter in versions up to, and including, 4.2 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts in pages that will execute whenever a user...
- CVSS:
- 6.1
- Affected:
- up to 4.3
- Fixed in:
- 4.3
- Disclosed:
- Aug 25, 2015
CVE-2016-10896 on NVD →
SEO Redirection <= 2.8 - Reflected Cross-Site Scripting
medium
The SEO Redirection Plugin – 301 Redirect Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘search’ parameter in versions before 2.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pag...
- CVSS:
- 6.1
- Affected:
- up to 2.9
- Fixed in:
- 2.9
- Disclosed:
- Aug 21, 2015
SEO Redirection Plugin – 301 Redirect Manager [seo-redirection] < 2.9
unknown
Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code.
Update the plugin.
- Affected:
- up to 2.9
- Fixed in:
- 2.9
- Disclosed:
- Aug 21, 2015
SEO Redirection Plugin – 301 Redirect Manager [seo-redirection] < 2.9
unknown
The SEO Redirection Plugin – 301 Redirect Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘search’ parameter in versions before 2.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pag...
- Affected:
- up to 2.9
- Fixed in:
- 2.9
- Disclosed:
- Aug 21, 2015
SEO Redirection Plugin – 301 Redirect Manager [seo-redirection] < 2.3
unknown
Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code.
Update the plugin.
- Affected:
- up to 2.3
- Fixed in:
- 2.3
- Disclosed:
- Dec 15, 2014
SEO Redirection Plugin – 301 Redirect Manager [seo-redirection] < 2.9
unknown
The plugin was affected by an Authenticated Reflected Cross-Site Scripting (XSS) security vulnerability in its settings page, via the search GET parameter
- Affected:
- up to 2.9
- Fixed in:
- 2.9
SEO Redirection Plugin – 301 Redirect Manager [seo-redirection] < 2.3
unknown
The plugin did not sanitise the referer link from requests before displaying them in the 'Settings > SEO Redirection > Redirection History' page. This result in a Store dCross-Site Scripting (XSS) issue
- Affected:
- up to 2.3
- Fixed in:
- 2.3
SEO Redirection Plugin – 301 Redirect Manager [seo-redirection] < 7.9
unknown
The plugin does have CSRF in place, allowing attackers to make logged in admin delete arbitrary Custom and Post Redirects via a CSRF attack.
- Affected:
- up to 7.9
- Fixed in:
- 7.9
SEO Redirection Plugin – 301 Redirect Manager [seo-redirection] < 7.4
unknown
The plugin does not escape the tab parameter before outputting it back in JavaScript code, leading to a Reflected Cross-Site Scripting issue
- Affected:
- up to 7.4
- Fixed in:
- 7.4
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database