CVE Database /
CVE-2021-24352
CVE · High
CVE-2021-24352 — Simple 301 Redirects By BetterLinks – Easy WordPress Redirect Manager for Redirects, 404 Error Log & More [simple-301-redirects] >= 2.0.0 - <= 2.0.3
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2021-24352
|
Simple 301 Redirects By BetterLinks – Easy WordPress Redirect Manager for Redirects, 404 Error Log & More [simple-301-redirects] >= 2.0.0 - <= 2.0.3 |
Missing Authorization |
High
8.8
|
2.0.0–2.0.4
|
2.0.4 |
2021-05-26 |
—
|
CVE-2021-24352
The Simple 301 Redirects by BetterLinks plugin through version 2.0.3 contains a vulnerability in its export_data function that lacks proper authentication and nonce validation, allowing any unauthenticated user to download and view all of the site's configured redirects. This flaw exposes redirect data that could reveal sensitive information about site structure and functionality. The vulnerability was fixed in version 2.0.4.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings