Simple 301 Redirects Addon Bulk Uploader <= 1.2.4 - Missing Authorization
high
The simple-301-redirects-addon-bulk-uploader plugin before 1.2.5 for WordPress has no protection against 301 redirect rule injection via a CSV file.
- CVSS:
- 7.2
- Affected:
- up to 1.2.5
- Fixed in:
- 1.2.5
- Disclosed:
- Aug 10, 2019
CVE-2019-15776 on NVD →
Simple 301 Redirects Addon Bulk Uploader <= 1.2.4 - Missing Authentication on Option Changes
medium
The simple-301-redirects-addon-bulk-uploader plugin through 1.2.4 for WordPress has no requirement for authentication for action=bulk301export or action=bulk301clearlist.
- CVSS:
- 6.1
- Affected:
- up to 1.2.5
- Fixed in:
- 1.2.5
- Disclosed:
- Aug 10, 2019
CVE-2019-15818 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database