CVE Database /
CVE-2021-24847
CVE · High
CVE-2021-24847 — SEO Redirection Plugin – 301 Redirect Manager [seo-redirection] < 9.1
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2021-24847
|
SEO Redirection Plugin – 301 Redirect Manager [seo-redirection] < 9.1 |
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') |
High
8.8
|
< 9.1
|
9.1 |
2021-10-18 |
—
|
CVE-2021-24847
The SEO Redirection Plugin – 301 Redirect Manager versions prior to 8.2 contains a SQL injection vulnerability in the importFromRedirection AJAX action that is accessible to any logged-in user. An attacker with authentication credentials could exploit inadequate sanitization of the offset parameter to execute arbitrary SQL queries. This vulnerability requires that both the vulnerable SEO Redirection plugin and the Redirection plugin be installed on the same WordPress installation.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings