CVE · Medium

CVE-2021-24355 — Simple 301 Redirects By BetterLinks – Easy WordPress Redirect Manager for Redirects, 404 Error Log & More [simple-301-redirects] >= 2.0.0 - <= 2.0.3

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2021-24355 Simple 301 Redirects By BetterLinks – Easy WordPress Redirect Manager for Redirects, 404 Error Log & More [simple-301-redirects] >= 2.0.0 - <= 2.0.3 Missing Authorization Medium 4.3 2.0.0–2.0.4 2.0.4 2021-05-26

CVE-2021-24355

The Simple 301 Redirects by BetterLinks plugin versions 2.0.0 through 2.0.3 contained inadequate permission validation and nonce verification in two AJAX functions handling wildcard redirect operations. This vulnerability allowed any authenticated user to both retrieve and modify wildcard redirect settings, regardless of their actual authorization level. The flaw was addressed in version 2.0.4.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.