WP Clinic
Entrar Registrarse

SEGURIDAD DE PLUGINS

¿Es seguro All 404 Redirect To Homepage?

Vulnerabilidades conocidas, compatibilidad con PHP y alternativas más seguras para el plugin de WordPress All 404 Redirect To Homepage — verificado contra la base de datos de seguridad local de WP Clinic.

Qué hace este plugin

  • Slug: all-404-redirect-to-homepage
  • 200000+ instalaciones activas

404 errorbroken imagesredirectionseo redirect

Estado de mantenimiento

  • Última versión conocida: 5.6
  • PHP máximo soportado (analizado): 8.4

Vulnerabilidades conocidas

1 CVE conocido registrado para All 404 Redirect To Homepage. Reportadas entre 2021 y 2021.

CVE Vulnerabilidad Tipo Gravedad Afectadas Corregido en Publicado Estado
All 404 Redirect to Homepage [all-404-redirect-to-homepage] < 2.1 Desconocido < 2.1 2.1 2021-06-01 ✓ corregido en la última versión
All 404 Redirect to Homepage [all-404-redirect-to-homepage] < 2.1 Desconocido < 2.1 2.1 2021-06-01 ✓ corregido en la última versión
All 404 Redirect to Homepage [all-404-redirect-to-homepage] < 1.21 Desconocido < 1.21 1.21 2021-04-21 ✓ corregido en la última versión
All 404 Redirect to Homepage [all-404-redirect-to-homepage] < 1.21 Desconocido < 1.21 1.21 2021-04-21 ✓ corregido en la última versión
CVE-2021-24326 All 404 Redirect to Homepage [all-404-redirect-to-homepage] < 1.21 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 1.21 1.21 2021-04-16 ✓ corregido en la última versión
All 404 Redirect to Homepage [all-404-redirect-to-homepage] < 2.1 Desconocido < 2.1 2.1 ✓ corregido en la última versión

All 404 Redirect to Homepage [all-404-redirect-to-homepage] < 2.1

Authenticated Stored Cross-Site Scripting (XSS) vulnerability discovered by WPScanTeam in WordPress All 404 Redirect to Homepage plugin (versions <= 1.21).

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

All 404 Redirect to Homepage [all-404-redirect-to-homepage] < 2.1

The All 404 Redirect to Homepage & Broken images Redirection plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 2.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

All 404 Redirect to Homepage [all-404-redirect-to-homepage] < 1.21

Authenticated Persistent Cross-Site Scripting (XSS) vulnerability discovered by m0ze (Patchstack Red Team) in WordPress All 404 Redirect to Homepage plugin (versions <= 1.20).

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

All 404 Redirect to Homepage [all-404-redirect-to-homepage] < 1.21

Authenticated Reflected Cross-Site Scripting (XSS) vulnerability discovered by m0ze (Patchstack Red Team) in WordPress All 404 Redirect to Homepage plugin (versions <= 1.20).

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2021-24326

The tab parameter of the settings page of the All 404 Redirect to Homepage WordPress plugin before 1.21 was vulnerable to an authenticated reflected Cross-Site Scripting (XSS) issue as user input was not properly sanitised before being output in an attribute.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

All 404 Redirect to Homepage [all-404-redirect-to-homepage] < 2.1

The plugin (v1.21) attempted to fix a Stored Cross-Site scripting issue in its "Redirect All 404 page to" settings, however the fix is insufficient, still allowing the issue to be triggered. This could allow high privilege users (even with the unfiltered_html disabled) to use malicious payloads in it, leading to a Stored XSS issue. The vendor was notified on April 27th, 2021 about it via the WP plugins team. v2.1 fixing the issue was released on August 16th, 2021

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

Cómo solucionarlo

Mantén All 404 Redirect To Homepage actualizado — 5.6 es la última versión en wordpress.org, y cada CVE de arriba indica la versión exacta que lo corrigió ("Corregido en").

Este es el historial completo de vulnerabilidades conocidas del plugin, no un escaneo de una instalación específica — ejecuta un escaneo gratis de tu propio sitio para verificar tu versión instalada exacta.

Alternativas más seguras / más establecidas

Verifica tu propio sitio WordPress

Ejecuta un escaneo pasivo gratis ahora, o crea una cuenta gratuita e instala el plugin de WP Clinic para un escaneo profundo de toda tu cuenta de hosting y reparación asistida por IA.