plugin

Simple 301 Redirects Addon Bulk Uploader Vulnerabilities

2 known security issues reported for the Simple 301 Redirects Addon Bulk Uploader WordPress plugin. Most recent disclosed Aug 10, 2019.

1 high 1 medium

Running Simple 301 Redirects Addon Bulk Uploader on your site? Check whether your installed version is affected.

Scan your site free

Simple 301 Redirects Addon Bulk Uploader <= 1.2.4 - Missing Authorization

high

The simple-301-redirects-addon-bulk-uploader plugin before 1.2.5 for WordPress has no protection against 301 redirect rule injection via a CSV file.

CVSS:
7.2
Affected:
up to 1.2.5
Fixed in:
1.2.5
Disclosed:
Aug 10, 2019

CVE-2019-15776 on NVD →

Simple 301 Redirects Addon Bulk Uploader <= 1.2.4 - Missing Authentication on Option Changes

medium

The simple-301-redirects-addon-bulk-uploader plugin through 1.2.4 for WordPress has no requirement for authentication for action=bulk301export or action=bulk301clearlist.

CVSS:
6.1
Affected:
up to 1.2.5
Fixed in:
1.2.5
Disclosed:
Aug 10, 2019

CVE-2019-15818 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database