WP Clinic
Entrar Registrarse

SEGURIDAD DE PLUGINS

¿Es seguro Redirect Redirection?

Vulnerabilidades conocidas, compatibilidad con PHP y alternativas más seguras para el plugin de WordPress Redirect Redirection — verificado contra la base de datos de seguridad local de WP Clinic.

Qué hace este plugin

  • Slug: redirect-redirection
  • 100000+ instalaciones activas

301404redirectredirectionredirects

Estado de mantenimiento

  • Última versión conocida: 1.3.0
  • Requiere PHP: 5.6+
  • PHP máximo soportado (analizado): 8.4

Vulnerabilidades conocidas

6 CVEs conocidos registrados para Redirect Redirection. Reportadas entre 2023 y 2024.

CVE Vulnerabilidad Tipo Gravedad Afectadas Corregido en Publicado Estado
CVE-2023-38514 Redirection [redirect-redirection] < 1.1.4 Falta de control de autorización Media 4,3 < 1.1.4 1.1.4 2024-12-13 ✓ corregido en la última versión
CVE-2024-31435 Redirection [redirect-redirection] < 1.2.0 Falta de control de autorización Media 4,3 < 1.2.0 1.2.0 2024-04-10 ✓ corregido en la última versión
CVE-2023-0958 Redirection [redirect-redirection] < 1.1.4 Falta de control de autorización Media 6,5 < 1.1.4 1.1.4 2023-07-27 ✓ corregido en la última versión
CVE-2023-3977 Redirection [redirect-redirection] < 1.1.4 Falsificación de petición en sitios cruzados (CSRF) Media 4,3 < 1.1.4 1.1.4 2023-07-27 ✓ corregido en la última versión
CVE-2023-1330 Redirection [redirect-redirection] < 1.1.5 Falsificación de petición en sitios cruzados (CSRF) Media 6,5 < 1.1.5 1.1.5 2023-04-03 ✓ corregido en la última versión
CVE-2023-1331 Redirection [redirect-redirection] < 1.1.5 Falsificación de petición en sitios cruzados (CSRF) Media 6,5 < 1.1.5 1.1.5 2023-03-21 ✓ corregido en la última versión
Redirection [redirect-redirection] < 1.1.5 Desconocido < 1.1.5 1.1.5 2023-03-15 ✓ corregido en la última versión
Redirection [redirect-redirection] < 1.1.5 Desconocido < 1.1.5 1.1.5 2023-03-14 ✓ corregido en la última versión

CVE-2023-38514

Missing Authorization vulnerability in social share pro Social Share Icons & Social Share Buttons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Social Share Icons & Social Share Buttons: from n/a through 3.5.7.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2024-31435

Update the WordPress Redirect Redirection plugin to the latest available version (at least 1.2.0). Dhabaleshwar Das discovered and reported this Broken Access Control vulnerability in WordPress Redirect Redirection Plugin. A broken access control issue refers to a missing authorization, authentication or nonce token check in a function that could lead to an unprivileged user to executing a certain higher privileged action. This vulnerability has been fixed in version 1.2.0. This vulnerability was reported to and published by Patchstack. Our users receive alerts and protections up to 48 hours in advance. Have additional information or questions about this entry? Get in touch.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2023-0958

Several plugins for WordPress by Inisev are vulnerable to unauthorized installation of plugins due to a missing capability check on the handle_installation function that is called via the inisev_installation AJAX aciton in various versions. This makes it possible for authenticated attackers with minimal permissions, such as subscribers, to install select plugins from Inisev on vulnerable sites. CVE-2023-38514 appears to be a duplicate of this vulnerability.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2023-3977

Several plugins for WordPress by Inisev are vulnerable to Cross-Site Request Forgery to unauthorized installation of plugins due to a missing nonce check on the handle_installation function that is called via the inisev_installation AJAX aciton in various versions. This makes it possible for unauthenticated attackers to install plugins from the limited list via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2023-1330

The Redirection WordPress plugin before 1.1.4 does not add nonce verification in place when adding the redirect, which could allow attackers to add redirects via a CSRF attack.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2023-1331

The Redirection plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.4. This is due to missing or incorrect nonce validation on the 'uninstall' function hooked via admin_post. This makes it possible for unauthenticated attackers to deactivate and reset the plugin via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Redirection [redirect-redirection] < 1.1.5

Update the WordPress Redirect Redirection plugin to the latest available version (at least 1.1.5). Unknown discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress Redirect Redirection Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted actions under their current authentication. This vulnerability has been fixed in version 1.1.5.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

Redirection [redirect-redirection] < 1.1.5

The Redirect Redirection plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.4. This is due to missing nonce validation on the uninstall() function called via an admin_post hook. This makes it possible for unauthenticated attackers to uninstall the plugin via a forged request, granted they can trick a site administrator into performing an action such as clicking on a link.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

+ 26 vulnerabilidades conocidas más
CVE Vulnerabilidad Tipo Gravedad Afectadas Corregido en Publicado Estado
Redirection [redirect-redirection] < 1.1.4 Desconocido < 1.1.4 1.1.4 2023-02-22 ✓ corregido en la última versión
Redirection [redirect-redirection] < 1.1.4 Desconocido < 1.1.4 1.1.4 2023-02-22 ✓ corregido en la última versión
Redirection [redirect-redirection] < 1.1.4 Desconocido < 1.1.4 1.1.4 2023-02-22 ✓ corregido en la última versión
Redirection [redirect-redirection] < 1.1.4 Desconocido < 1.1.4 1.1.4 2023-02-21 ✓ corregido en la última versión
Redirection [redirect-redirection] < 1.1.4 Desconocido < 1.1.4 1.1.4 2023-02-21 ✓ corregido en la última versión
Redirection [redirect-redirection] < 1.1.4 Desconocido < 1.1.4 1.1.4 2023-02-21 ✓ corregido en la última versión
Redirection [redirect-redirection] < 1.1.4 Desconocido < 1.1.4 1.1.4 2023-02-21 ✓ corregido en la última versión
Redirection [redirect-redirection] < 1.1.4 Desconocido < 1.1.4 1.1.4 2023-02-21 ✓ corregido en la última versión
Redirection [redirect-redirection] < 1.1.4 Desconocido < 1.1.4 1.1.4 2023-02-21 ✓ corregido en la última versión
Redirection [redirect-redirection] < 1.1.4 Desconocido < 1.1.4 1.1.4 2023-02-21 ✓ corregido en la última versión
Redirection [redirect-redirection] < 1.1.4 Desconocido < 1.1.4 1.1.4 2023-02-21 ✓ corregido en la última versión
Redirection [redirect-redirection] < 1.1.4 Desconocido < 1.1.4 1.1.4 2023-02-21 ✓ corregido en la última versión
Redirection [redirect-redirection] < 1.1.4 Desconocido < 1.1.4 1.1.4 2023-02-21 ✓ corregido en la última versión
Redirection [redirect-redirection] < 1.1.4 Desconocido < 1.1.4 1.1.4 2023-02-21 ✓ corregido en la última versión
Redirection [redirect-redirection] < 1.1.4 Desconocido < 1.1.4 1.1.4 2023-02-21 ✓ corregido en la última versión
Redirection [redirect-redirection] < 1.1.4 Desconocido < 1.1.4 1.1.4 2023-02-21 ✓ corregido en la última versión
Redirection [redirect-redirection] < 1.1.4 Desconocido < 1.1.4 1.1.4 2023-02-21 ✓ corregido en la última versión
Redirection [redirect-redirection] < 1.1.4 Desconocido < 1.1.4 1.1.4 2023-02-21 ✓ corregido en la última versión
Redirection [redirect-redirection] < 1.1.4 Desconocido < 1.1.4 1.1.4 2023-02-21 ✓ corregido en la última versión
Redirection [redirect-redirection] < 1.1.4 Desconocido < 1.1.4 1.1.4 2023-02-21 ✓ corregido en la última versión
Redirection [redirect-redirection] < 1.1.4 Desconocido < 1.1.4 1.1.4 2023-02-21 ✓ corregido en la última versión
Redirection [redirect-redirection] < 1.1.4 Desconocido < 1.1.4 1.1.4 2023-02-21 ✓ corregido en la última versión
Redirection [redirect-redirection] < 1.1.4 Desconocido < 1.1.4 1.1.4 2023-02-21 ✓ corregido en la última versión
Redirection [redirect-redirection] < 1.1.4 Desconocido < 1.1.4 1.1.4 2023-02-21 ✓ corregido en la última versión
Redirection [redirect-redirection] < 1.1.4 Desconocido < 1.1.4 1.1.4 2023-02-21 ✓ corregido en la última versión
Redirection [redirect-redirection] < 1.1.4 Desconocido < 1.1.4 1.1.4 2023-02-21 ✓ corregido en la última versión

Redirection [redirect-redirection] < 1.1.4

The Redirect Redirection plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3. This is due to missing or incorrect nonce validation on the addRedirect function. This makes it possible for unauthenticated attackers to add redirects, via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Redirection [redirect-redirection] < 1.1.4

The Redirect Redirection plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the LoadTab function called via an AJAX action in versions up to, and including, 1.1.3. This makes it possible for authenticated attackers with subscriber-level access, and above, to load tabs.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Redirection [redirect-redirection] < 1.1.4

Update the WordPress Redirect Redirection plugin to the latest available version (at least 1.1.4). WordFence discovered and reported this Broken Access Control vulnerability in WordPress Redirect Redirection Plugin. This vulnerability has been fixed in version 1.1.4.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

Redirection [redirect-redirection] < 1.1.4

The Redirect Redirection plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the logFilter function in versions up to, and including, 1.1.3. This makes it possible for authenticated attackers with subscriber-level access, and above, to filter and view logs.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Redirection [redirect-redirection] < 1.1.4

The Redirect Redirection plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the logPageContent function called via an AJAX action in versions up to, and including, 1.1.3. This makes it possible for authenticated attackers with subscriber-level access, and above, to view redirect logs.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Redirection [redirect-redirection] < 1.1.4

The Redirect Redirection plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the saveRedirectSettings function called via an AJAX action in versions up to, and including, 1.1.3. This makes it possible for authenticated attackers with subscriber-level access, and above, to modify the plugin's redirect settings.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Redirection [redirect-redirection] < 1.1.4

The Redirect Redirection plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the selectAll function in versions up to, and including, 1.1.3. This makes it possible for authenticated attackers with subscriber-level access, and above, to retrieve specific redirects.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Redirection [redirect-redirection] < 1.1.4

The Redirect Redirection plugin for WordPress is vulnerable to unauthorized modification of settings due to a missing capability check on the deleteRedirect function called via an AJAX action in versions up to, and including, 1.1.3. This makes it possible for authenticated attackers with subscriber-level access, and above, to delete site redirects.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Redirection [redirect-redirection] < 1.1.4

The Redirect Redirection plugin for WordPress is vulnerable to unauthorized disclosure of data due to a missing capability check on the loadRedirectSettings function called via an AJAX action in versions up to, and including, 1.1.3. This makes it possible for authenticated attackers with subscriber-level access, and above, to load and view redirect settings.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Redirection [redirect-redirection] < 1.1.4

The Redirect Redirection plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the instantEditRedirect function called via an AJAX action in versions up to, and including, 1.1.3. This makes it possible for authenticated attackers with subscriber-level access, and above, to modify existing redirects on a vulnerable site.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Redirection [redirect-redirection] < 1.1.4

The Redirect Redirection plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the addRedirectRule function called via an AJAX action in versions up to, and including, 1.1.3. This makes it possible for authenticated attackers with subscriber-level access, and above, to add redirect rules to a vulnerable site.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Redirection [redirect-redirection] < 1.1.4

The Redirect Redirection plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the bulkDelete function called via an AJAX action in versions up to, and including, 1.1.3. This makes it possible for authenticated attackers with subscriber-level access, and above, to bulk delete redirect rules.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Redirection [redirect-redirection] < 1.1.4

The Redirect Redirection plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the addRedirect function called via an AJAX action in versions up to, and including, 1.1.3. This makes it possible for authenticated attackers with subscriber-level access, and above, to add redirects to a vulnerable site.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Redirection [redirect-redirection] < 1.1.4

The Redirect Redirection plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the liveSearch function called via an AJAX action in versions up to, and including, 1.1.3. This makes it possible for authenticated attackers with subscriber-level access, and above, to search redirect rules and settings.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Redirection [redirect-redirection] < 1.1.4

The Redirect Redirection plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the statusBulkEdit function called via an AJAX action in versions up to, and including, 1.1.3. This makes it possible for authenticated attackers with subscriber-level access, and above, to edit redirect rule statuses in bulk.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Redirection [redirect-redirection] < 1.1.4

The Redirect Redirection plugin for WordPress is vulnerable to unauthorized disclosure of data due to a missing capability check on the redirectionPageContent function called via an AJAX action in versions up to, and including, 1.1.3. This makes it possible for authenticated attackers with subscriber-level access, and above, to retrieve existing redirect rules.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Redirection [redirect-redirection] < 1.1.4

The Redirect Redirection plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the loadSettings function in versions up to, and including, 1.1.3. This makes it possible for authenticated attackers with subscriber-level access, and above, to load the plugin's settings.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Redirection [redirect-redirection] < 1.1.4

The Redirect Redirection plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3. This is due to missing or incorrect nonce validation on the SaveSettings function. This makes it possible for unauthenticated attackers to update the plugin's settings, via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Redirection [redirect-redirection] < 1.1.4

The Redirect Redirection plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the SaveSettings function called via an AJAX action in versions up to, and including, 1.1.3. This makes it possible for authenticated attackers with subscriber-level access, and above, to modify the plugin's settings.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Redirection [redirect-redirection] < 1.1.4

The Redirect Redirection plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3. This is due to missing or incorrect nonce validation on the saveRedirectSettings function. This makes it possible for unauthenticated attackers to modify redirect settings, via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Redirection [redirect-redirection] < 1.1.4

The Redirect Redirection plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3. This is due to missing or incorrect nonce validation on the addRedirectRule function. This makes it possible for unauthenticated attackers to add redirect rules, via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Redirection [redirect-redirection] < 1.1.4

The Redirect Redirection plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3. This is due to missing or incorrect nonce validation on the statusBulkEdit function. This makes it possible for unauthenticated attackers to bulk edit redirect rules, via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Redirection [redirect-redirection] < 1.1.4

The Redirect Redirection plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3. This is due to missing or incorrect nonce validation on the cronLogDeleteOption function. This makes it possible for unauthenticated attackers to delete cronLog options, via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Redirection [redirect-redirection] < 1.1.4

The Redirect Redirection plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3. This is due to missing or incorrect nonce validation on the deleteRedirect function. This makes it possible for unauthenticated attackers to delete redirects, via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Redirection [redirect-redirection] < 1.1.4

The Redirect Redirection plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3. This is due to missing or incorrect nonce validation on the instantEditRedirect function. This makes it possible for unauthenticated attackers to edit redirects via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Redirection [redirect-redirection] < 1.1.4

The Redirect Redirection plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3. This is due to missing or incorrect nonce validation on the bulkDelete function. This makes it possible for unauthenticated attackers to delete redirect rules in bulk, via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Cómo solucionarlo

Mantén Redirect Redirection actualizado — 1.3.0 es la última versión en wordpress.org, y cada CVE de arriba indica la versión exacta que lo corrigió ("Corregido en").

Este es el historial completo de vulnerabilidades conocidas del plugin, no un escaneo de una instalación específica — ejecuta un escaneo gratis de tu propio sitio para verificar tu versión instalada exacta.

Alternativas más seguras / más establecidas

Verifica tu propio sitio WordPress

Ejecuta un escaneo pasivo gratis ahora, o crea una cuenta gratuita e instala el plugin de WP Clinic para un escaneo profundo de toda tu cuenta de hosting y reparación asistida por IA.