CVE · High

CVE-2021-24847 — SEO Redirection Plugin – 301 Redirect Manager [seo-redirection] < 9.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2021-24847 SEO Redirection Plugin – 301 Redirect Manager [seo-redirection] < 9.1 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') High 8.8 < 9.1 9.1 2021-10-18

CVE-2021-24847

The SEO Redirection Plugin – 301 Redirect Manager versions prior to 8.2 contains a SQL injection vulnerability in the importFromRedirection AJAX action that is accessible to any logged-in user. An attacker with authentication credentials could exploit inadequate sanitization of the offset parameter to execute arbitrary SQL queries. This vulnerability requires that both the vulnerable SEO Redirection plugin and the Redirection plugin be installed on the same WordPress installation.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.