CVE Database /
CVE-2021-24355
CVE · Medium
CVE-2021-24355 — Simple 301 Redirects By BetterLinks – Easy WordPress Redirect Manager for Redirects, 404 Error Log & More [simple-301-redirects] >= 2.0.0 - <= 2.0.3
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2021-24355
|
Simple 301 Redirects By BetterLinks – Easy WordPress Redirect Manager for Redirects, 404 Error Log & More [simple-301-redirects] >= 2.0.0 - <= 2.0.3 |
Missing Authorization |
Medium
4.3
|
2.0.0–2.0.4
|
2.0.4 |
2021-05-26 |
—
|
CVE-2021-24355
The Simple 301 Redirects by BetterLinks plugin versions 2.0.0 through 2.0.3 contained inadequate permission validation and nonce verification in two AJAX functions handling wildcard redirect operations. This vulnerability allowed any authenticated user to both retrieve and modify wildcard redirect settings, regardless of their actual authorization level. The flaw was addressed in version 2.0.4.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings