Simple 301 Redirects By BetterLinks – Easy Redirect Manager for WP, 404 Error Log & More [simple-301-redirects] < 2.0.8
unknown
[en] Missing Authorization vulnerability in WPDeveloper Simple 301 Redirects by BetterLinks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simple 301 Redirects by BetterLinks: from n/a through 2.0.7.
- Affected:
- up to 2.0.8
- Fixed in:
- 2.0.8
- Disclosed:
- Dec 9, 2024
CVE-2023-47761 on NVD →
Simple 301 Redirects by BetterLinks <= 2.0.7 - Missing Authorization via clicked
medium
The Simple 301 Redirects by BetterLinks plugin for WordPress is vulnerable to unauthorized enabling of plugin usage tracking due to a missing capability check on the clicked function in all versions up to, and including, 2.0.7. This makes it possible for subscribers to enable plugin tracking.
- CVSS:
- 4.3
- Affected:
- up to 2.0.7
- Fixed in:
- 2.0.8
- Disclosed:
- Nov 13, 2023
CVE-2023-47761 on NVD →
Simple 301 Redirects <= 2.0.7 - Cross-Site Request Forgery via 'clicked'
medium
The Simple 301 Redirects plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.7. This is due to missing or incorrect nonce validation on the 'clicked' function. This makes it possible for unauthenticated attackers to enable or disable click tracking via a forged request...
- CVSS:
- 5.4
- Affected:
- up to 2.0.8
- Fixed in:
- 2.0.8
- Disclosed:
- Aug 30, 2023
Simple 301 Redirects By BetterLinks – Easy Redirect Manager for WP, 404 Error Log & More [simple-301-redirects] < 2.0.8
unknown
The Simple 301 Redirects plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.7. This is due to missing or incorrect nonce validation on the 'clicked' function. This makes it possible for unauthenticated attackers to enable or disable click tracking via a forged request...
- Affected:
- up to 2.0.8
- Fixed in:
- 2.0.8
- Disclosed:
- Aug 30, 2023
Simple 301 Redirects By BetterLinks – Easy Redirect Manager for WP, 404 Error Log & More [simple-301-redirects] >= 2.0.0 - <= 2.0.3
unknown
[en] In the Simple 301 Redirects by BetterLinks WordPress plugin before 2.0.4, a lack of capability checks and insufficient nonce check on the AJAX action, simple301redirects/admin/activate_plugin, made it possible for authenticated users to activate arbitrary plugins installed on vulnerable sites.
- Affected:
- 2.0.0 – 2.0.3
- Fixed in:
- 2.0.3
- Disclosed:
- Jun 14, 2021
CVE-2021-24356 on NVD →
Simple 301 Redirects By BetterLinks – Easy Redirect Manager for WP, 404 Error Log & More [simple-301-redirects] >= 2.0.0 - <= 2.0.3
unknown
[en] The import_data function of the Simple 301 Redirects by BetterLinks WordPress plugin before 2.0.4 had no capability or nonce checks making it possible for unauthenticated users to import a set of site redirects.
- Affected:
- 2.0.0 – 2.0.3
- Fixed in:
- 2.0.3
- Disclosed:
- Jun 14, 2021
CVE-2021-24353 on NVD →
Simple 301 Redirects By BetterLinks – Easy Redirect Manager for WP, 404 Error Log & More [simple-301-redirects] >= 2.0.0 - <= 2.0.3
unknown
[en] The export_data function of the Simple 301 Redirects by BetterLinks WordPress plugin before 2.0.4 had no capability or nonce checks making it possible for unauthenticated users to export a site's redirects.
- Affected:
- 2.0.0 – 2.0.3
- Fixed in:
- 2.0.3
- Disclosed:
- Jun 14, 2021
CVE-2021-24352 on NVD →
Simple 301 Redirects By BetterLinks – Easy Redirect Manager for WP, 404 Error Log & More [simple-301-redirects] >= 2.0.0 - <= 2.0.3
unknown
[en] A lack of capability checks and insufficient nonce check on the AJAX action in the Simple 301 Redirects by BetterLinks WordPress plugin before 2.0.4, made it possible for authenticated users to install arbitrary plugins on vulnerable sites.
- Affected:
- 2.0.0 – 2.0.3
- Fixed in:
- 2.0.3
- Disclosed:
- Jun 14, 2021
CVE-2021-24354 on NVD →
Simple 301 Redirects By BetterLinks – Easy Redirect Manager for WP, 404 Error Log & More [simple-301-redirects] >= 2.0.0 - <= 2.0.3
unknown
[en] In the Simple 301 Redirects by BetterLinks WordPress plugin before 2.0.4, the lack of capability checks and insufficient nonce check on the AJAX actions, simple301redirects/admin/get_wildcard and simple301redirects/admin/wildcard, made it possible for authenticated users to retrieve and update the wildcard value f...
- Affected:
- 2.0.0 – 2.0.3
- Fixed in:
- 2.0.3
- Disclosed:
- Jun 14, 2021
CVE-2021-24355 on NVD →
Simple 301 Redirects 2.0.0 - 2.0.3 - Unauthenticated Redirect Export
high
The export_data function of the Simple 301 Redirects by BetterLinks WordPress plugin before 2.0.4 had no capability or nonce checks making it possible for unauthenticated users to export a site's redirects.
- CVSS:
- 8.8
- Affected:
- 2.0.0 – 2.0.3
- Fixed in:
- 2.0.4
- Disclosed:
- May 26, 2021
CVE-2021-24352 on NVD →
Simple 301 Redirects 2.0.0 - 2.0.3 - Unauthenticated Redirect Import
high
The import_data function of the Simple 301 Redirects by BetterLinks WordPress plugin before 2.0.4 had no capability or nonce checks making it possible for unauthenticated users to import a set of site redirects.
- CVSS:
- 8.8
- Affected:
- 2.0.0 – 2.0.3
- Fixed in:
- 2.0.4
- Disclosed:
- May 26, 2021
CVE-2021-24353 on NVD →
Simple 301 Redirects 2.0.0 - 2.0.3 - Authenticated Arbitrary Plugin Activation
high
In the Simple 301 Redirects by BetterLinks WordPress plugin before 2.0.4, a lack of capability checks and insufficient nonce check on the AJAX action, simple301redirects/admin/activate_plugin, made it possible for authenticated users to activate arbitrary plugins installed on vulnerable sites.
- CVSS:
- 8.8
- Affected:
- 2.0.0 – 2.0.3
- Fixed in:
- 2.0.4
- Disclosed:
- May 26, 2021
CVE-2021-24356 on NVD →
Simple 301 Redirects 2.0.0 - 2.0.3 - Authenticated Arbitrary Plugin Installation
high
A lack of capability checks and insufficient nonce check on the AJAX action in the Simple 301 Redirects by BetterLinks WordPress plugin before 2.0.4, made it possible for authenticated users to install arbitrary plugins on vulnerable sites.
- CVSS:
- 8.8
- Affected:
- 2.0.0 – 2.0.3
- Fixed in:
- 2.0.4
- Disclosed:
- May 26, 2021
CVE-2021-24354 on NVD →
Simple 301 Redirects 2.0.0 - 2.0.3 - Authenticated Wildcard Activation and Retrieval
medium
In the Simple 301 Redirects by BetterLinks WordPress plugin before 2.0.4, the lack of capability checks and insufficient nonce check on the AJAX actions, simple301redirects/admin/get_wildcard and simple301redirects/admin/wildcard, made it possible for authenticated users to retrieve and update the wildcard value for re...
- CVSS:
- 4.3
- Affected:
- 2.0.0 – 2.0.3
- Fixed in:
- 2.0.4
- Disclosed:
- May 26, 2021
CVE-2021-24355 on NVD →
Simple 301 Redirects By BetterLinks – Easy Redirect Manager for WP, 404 Error Log & More [simple-301-redirects] < 2.0.4
unknown
Unauthenticated Redirect Import/Export vulnerability Allowing Total Site Redirection discovered by WordFence in WordPress Simple 301 Redirects by BetterLinks plugin (versions <= 2.0.3 only versions from 2.0.0 to 2.0.3).
- Affected:
- up to 2.0.4
- Fixed in:
- 2.0.4
- Disclosed:
- May 26, 2021
Simple 301 Redirects By BetterLinks – Easy Redirect Manager for WP, 404 Error Log & More [simple-301-redirects] >= 2.0.0 - <= 2.0.3
unknown
Authenticated Arbitrary Plugin Installation/Activation vulnerability discovered by WordFence in WordPress Simple 301 Redirects by BetterLinks plugin (versions <= 2.0.3 only versions from 2.0.0 to 2.0.3).
- Affected:
- 2.0.0 – 2.0.3
- Fixed in:
- 2.0.3
- Disclosed:
- May 26, 2021
Simple 301 Redirects By BetterLinks – Easy Redirect Manager for WP, 404 Error Log & More [simple-301-redirects] >= 2.0.0 - <= 2.0.3
unknown
Authenticated Wildcard Activation and Retrieval vulnerability discovered by WordFence in WordPress Simple 301 Redirects by BetterLinks plugin (versions <= 2.0.3 only versions 2.0.0 – 2.0.3).
- Affected:
- 2.0.0 – 2.0.3
- Fixed in:
- 2.0.3
- Disclosed:
- May 26, 2021
Simple 301 Redirects By BetterLinks – Easy Redirect Manager for WP, 404 Error Log & More [simple-301-redirects] < 1.2.5
unknown
Unauthenticated option changes and other security issues found by Jerome Bruandet (Nintechnet) in WordPress Simple 301 Redirects Addon Bulk Uploader plugin (versions <= 1.2.4).
- Affected:
- up to 1.2.5
- Fixed in:
- 1.2.5
- Disclosed:
- Aug 12, 2019
Simple 301 Redirects By BetterLinks – Easy Redirect Manager for WP, 404 Error Log & More [simple-301-redirects] < 2.0.8
unknown
The Simple 301 Redirects plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.7. This is due to missing or incorrect nonce validation on the 'clicked' function. This makes it possible for unauthenticated attackers to enable or disable click tracking via a forg...
- Affected:
- up to 2.0.8
- Fixed in:
- 2.0.8
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database