6 CVEs conocidos registrados para Redirect Redirection.
Reportadas entre 2023 y 2024.
+ 26 vulnerabilidades conocidas más
| CVE |
Vulnerabilidad |
Tipo |
Gravedad |
Afectadas |
Corregido en |
Publicado |
Estado |
|
—
|
Redirection [redirect-redirection] < 1.1.4 |
— |
Desconocido
|
< 1.1.4
|
1.1.4 |
2023-02-22 |
✓ corregido en la última versión
|
|
—
|
Redirection [redirect-redirection] < 1.1.4 |
— |
Desconocido
|
< 1.1.4
|
1.1.4 |
2023-02-22 |
✓ corregido en la última versión
|
|
—
|
Redirection [redirect-redirection] < 1.1.4 |
— |
Desconocido
|
< 1.1.4
|
1.1.4 |
2023-02-22 |
✓ corregido en la última versión
|
|
—
|
Redirection [redirect-redirection] < 1.1.4 |
— |
Desconocido
|
< 1.1.4
|
1.1.4 |
2023-02-21 |
✓ corregido en la última versión
|
|
—
|
Redirection [redirect-redirection] < 1.1.4 |
— |
Desconocido
|
< 1.1.4
|
1.1.4 |
2023-02-21 |
✓ corregido en la última versión
|
|
—
|
Redirection [redirect-redirection] < 1.1.4 |
— |
Desconocido
|
< 1.1.4
|
1.1.4 |
2023-02-21 |
✓ corregido en la última versión
|
|
—
|
Redirection [redirect-redirection] < 1.1.4 |
— |
Desconocido
|
< 1.1.4
|
1.1.4 |
2023-02-21 |
✓ corregido en la última versión
|
|
—
|
Redirection [redirect-redirection] < 1.1.4 |
— |
Desconocido
|
< 1.1.4
|
1.1.4 |
2023-02-21 |
✓ corregido en la última versión
|
|
—
|
Redirection [redirect-redirection] < 1.1.4 |
— |
Desconocido
|
< 1.1.4
|
1.1.4 |
2023-02-21 |
✓ corregido en la última versión
|
|
—
|
Redirection [redirect-redirection] < 1.1.4 |
— |
Desconocido
|
< 1.1.4
|
1.1.4 |
2023-02-21 |
✓ corregido en la última versión
|
|
—
|
Redirection [redirect-redirection] < 1.1.4 |
— |
Desconocido
|
< 1.1.4
|
1.1.4 |
2023-02-21 |
✓ corregido en la última versión
|
|
—
|
Redirection [redirect-redirection] < 1.1.4 |
— |
Desconocido
|
< 1.1.4
|
1.1.4 |
2023-02-21 |
✓ corregido en la última versión
|
|
—
|
Redirection [redirect-redirection] < 1.1.4 |
— |
Desconocido
|
< 1.1.4
|
1.1.4 |
2023-02-21 |
✓ corregido en la última versión
|
|
—
|
Redirection [redirect-redirection] < 1.1.4 |
— |
Desconocido
|
< 1.1.4
|
1.1.4 |
2023-02-21 |
✓ corregido en la última versión
|
|
—
|
Redirection [redirect-redirection] < 1.1.4 |
— |
Desconocido
|
< 1.1.4
|
1.1.4 |
2023-02-21 |
✓ corregido en la última versión
|
|
—
|
Redirection [redirect-redirection] < 1.1.4 |
— |
Desconocido
|
< 1.1.4
|
1.1.4 |
2023-02-21 |
✓ corregido en la última versión
|
|
—
|
Redirection [redirect-redirection] < 1.1.4 |
— |
Desconocido
|
< 1.1.4
|
1.1.4 |
2023-02-21 |
✓ corregido en la última versión
|
|
—
|
Redirection [redirect-redirection] < 1.1.4 |
— |
Desconocido
|
< 1.1.4
|
1.1.4 |
2023-02-21 |
✓ corregido en la última versión
|
|
—
|
Redirection [redirect-redirection] < 1.1.4 |
— |
Desconocido
|
< 1.1.4
|
1.1.4 |
2023-02-21 |
✓ corregido en la última versión
|
|
—
|
Redirection [redirect-redirection] < 1.1.4 |
— |
Desconocido
|
< 1.1.4
|
1.1.4 |
2023-02-21 |
✓ corregido en la última versión
|
|
—
|
Redirection [redirect-redirection] < 1.1.4 |
— |
Desconocido
|
< 1.1.4
|
1.1.4 |
2023-02-21 |
✓ corregido en la última versión
|
|
—
|
Redirection [redirect-redirection] < 1.1.4 |
— |
Desconocido
|
< 1.1.4
|
1.1.4 |
2023-02-21 |
✓ corregido en la última versión
|
|
—
|
Redirection [redirect-redirection] < 1.1.4 |
— |
Desconocido
|
< 1.1.4
|
1.1.4 |
2023-02-21 |
✓ corregido en la última versión
|
|
—
|
Redirection [redirect-redirection] < 1.1.4 |
— |
Desconocido
|
< 1.1.4
|
1.1.4 |
2023-02-21 |
✓ corregido en la última versión
|
|
—
|
Redirection [redirect-redirection] < 1.1.4 |
— |
Desconocido
|
< 1.1.4
|
1.1.4 |
2023-02-21 |
✓ corregido en la última versión
|
|
—
|
Redirection [redirect-redirection] < 1.1.4 |
— |
Desconocido
|
< 1.1.4
|
1.1.4 |
2023-02-21 |
✓ corregido en la última versión
|
Redirection [redirect-redirection] < 1.1.4
The Redirect Redirection plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3. This is due to missing or incorrect nonce validation on the addRedirect function. This makes it possible for unauthenticated attackers to add redirects, via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
Redirection [redirect-redirection] < 1.1.4
The Redirect Redirection plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the LoadTab function called via an AJAX action in versions up to, and including, 1.1.3. This makes it possible for authenticated attackers with subscriber-level access, and above, to load tabs.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
Redirection [redirect-redirection] < 1.1.4
Update the WordPress Redirect Redirection plugin to the latest available version (at least 1.1.4).
WordFence discovered and reported this Broken Access Control vulnerability in WordPress Redirect Redirection Plugin. This vulnerability has been fixed in version 1.1.4.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
Redirection [redirect-redirection] < 1.1.4
The Redirect Redirection plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the logFilter function in versions up to, and including, 1.1.3. This makes it possible for authenticated attackers with subscriber-level access, and above, to filter and view logs.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
Redirection [redirect-redirection] < 1.1.4
The Redirect Redirection plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the logPageContent function called via an AJAX action in versions up to, and including, 1.1.3. This makes it possible for authenticated attackers with subscriber-level access, and above, to view redirect logs.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
Redirection [redirect-redirection] < 1.1.4
The Redirect Redirection plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the saveRedirectSettings function called via an AJAX action in versions up to, and including, 1.1.3. This makes it possible for authenticated attackers with subscriber-level access, and above, to modify the plugin's redirect settings.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
Redirection [redirect-redirection] < 1.1.4
The Redirect Redirection plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the selectAll function in versions up to, and including, 1.1.3. This makes it possible for authenticated attackers with subscriber-level access, and above, to retrieve specific redirects.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
Redirection [redirect-redirection] < 1.1.4
The Redirect Redirection plugin for WordPress is vulnerable to unauthorized modification of settings due to a missing capability check on the deleteRedirect function called via an AJAX action in versions up to, and including, 1.1.3. This makes it possible for authenticated attackers with subscriber-level access, and above, to delete site redirects.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
Redirection [redirect-redirection] < 1.1.4
The Redirect Redirection plugin for WordPress is vulnerable to unauthorized disclosure of data due to a missing capability check on the loadRedirectSettings function called via an AJAX action in versions up to, and including, 1.1.3. This makes it possible for authenticated attackers with subscriber-level access, and above, to load and view redirect settings.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
Redirection [redirect-redirection] < 1.1.4
The Redirect Redirection plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the instantEditRedirect function called via an AJAX action in versions up to, and including, 1.1.3. This makes it possible for authenticated attackers with subscriber-level access, and above, to modify existing redirects on a vulnerable site.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
Redirection [redirect-redirection] < 1.1.4
The Redirect Redirection plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the addRedirectRule function called via an AJAX action in versions up to, and including, 1.1.3. This makes it possible for authenticated attackers with subscriber-level access, and above, to add redirect rules to a vulnerable site.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
Redirection [redirect-redirection] < 1.1.4
The Redirect Redirection plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the bulkDelete function called via an AJAX action in versions up to, and including, 1.1.3. This makes it possible for authenticated attackers with subscriber-level access, and above, to bulk delete redirect rules.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
Redirection [redirect-redirection] < 1.1.4
The Redirect Redirection plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the addRedirect function called via an AJAX action in versions up to, and including, 1.1.3. This makes it possible for authenticated attackers with subscriber-level access, and above, to add redirects to a vulnerable site.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
Redirection [redirect-redirection] < 1.1.4
The Redirect Redirection plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the liveSearch function called via an AJAX action in versions up to, and including, 1.1.3. This makes it possible for authenticated attackers with subscriber-level access, and above, to search redirect rules and settings.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
Redirection [redirect-redirection] < 1.1.4
The Redirect Redirection plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the statusBulkEdit function called via an AJAX action in versions up to, and including, 1.1.3. This makes it possible for authenticated attackers with subscriber-level access, and above, to edit redirect rule statuses in bulk.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
Redirection [redirect-redirection] < 1.1.4
The Redirect Redirection plugin for WordPress is vulnerable to unauthorized disclosure of data due to a missing capability check on the redirectionPageContent function called via an AJAX action in versions up to, and including, 1.1.3. This makes it possible for authenticated attackers with subscriber-level access, and above, to retrieve existing redirect rules.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
Redirection [redirect-redirection] < 1.1.4
The Redirect Redirection plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the loadSettings function in versions up to, and including, 1.1.3. This makes it possible for authenticated attackers with subscriber-level access, and above, to load the plugin's settings.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
Redirection [redirect-redirection] < 1.1.4
The Redirect Redirection plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3. This is due to missing or incorrect nonce validation on the SaveSettings function. This makes it possible for unauthenticated attackers to update the plugin's settings, via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
Redirection [redirect-redirection] < 1.1.4
The Redirect Redirection plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the SaveSettings function called via an AJAX action in versions up to, and including, 1.1.3. This makes it possible for authenticated attackers with subscriber-level access, and above, to modify the plugin's settings.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
Redirection [redirect-redirection] < 1.1.4
The Redirect Redirection plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3. This is due to missing or incorrect nonce validation on the saveRedirectSettings function. This makes it possible for unauthenticated attackers to modify redirect settings, via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
Redirection [redirect-redirection] < 1.1.4
The Redirect Redirection plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3. This is due to missing or incorrect nonce validation on the addRedirectRule function. This makes it possible for unauthenticated attackers to add redirect rules, via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
Redirection [redirect-redirection] < 1.1.4
The Redirect Redirection plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3. This is due to missing or incorrect nonce validation on the statusBulkEdit function. This makes it possible for unauthenticated attackers to bulk edit redirect rules, via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
Redirection [redirect-redirection] < 1.1.4
The Redirect Redirection plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3. This is due to missing or incorrect nonce validation on the cronLogDeleteOption function. This makes it possible for unauthenticated attackers to delete cronLog options, via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
Redirection [redirect-redirection] < 1.1.4
The Redirect Redirection plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3. This is due to missing or incorrect nonce validation on the deleteRedirect function. This makes it possible for unauthenticated attackers to delete redirects, via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
Redirection [redirect-redirection] < 1.1.4
The Redirect Redirection plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3. This is due to missing or incorrect nonce validation on the instantEditRedirect function. This makes it possible for unauthenticated attackers to edit redirects via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
Redirection [redirect-redirection] < 1.1.4
The Redirect Redirection plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3. This is due to missing or incorrect nonce validation on the bulkDelete function. This makes it possible for unauthenticated attackers to delete redirect rules in bulk, via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
Mantén Redirect Redirection actualizado — 1.3.0 es la última versión en wordpress.org, y cada CVE de arriba indica la versión exacta que lo corrigió ("Corregido en").
Este es el historial completo de vulnerabilidades conocidas del plugin, no un escaneo de una instalación específica — ejecuta un escaneo gratis de tu propio sitio para verificar tu versión instalada exacta.