CVE-2019-19915
The 301 Redirects – Redirect Manager plugin before version 2.45 contains vulnerabilities in its /admin-ajax.php endpoints that allow authenticated users with subscriber-level permissions or higher to manipulate redirect rules through the eps_redirect_save and eps_redirect_delete actions. These flaws enable attackers to modify or remove redirects, inject malicious code through cross-site scripting, and potentially conduct cross-site request forgery attacks, leading to site unavailability, redirection to malicious destinations, and compromise of site visitors. The insufficient permission controls and lack of input validation create multiple attack vectors for both authenticated and unauthenticated exploitation.
Based on public CVE data (MITRE/NVD).