CVE · Medium

CVE-2021-4338 — 404 to 301 – Redirect Manager, 301 Redirection, 404 Error Logs & 404 Monitoring [404-to-301] < 3.0.8

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2021-4338 404 to 301 – Redirect Manager, 301 Redirection, 404 Error Logs & 404 Monitoring [404-to-301] < 3.0.8 Improper Access Control Medium 5.4 < 3.0.8 3.0.8 2021-06-18

CVE-2021-4338

The 404 to 301 plugin through version 3.0.7 contains an authorization bypass vulnerability where the open_redirect and save_redirect functions lack proper capability verification. Authenticated users can exploit this flaw to view, create, and modify redirections without the necessary permissions. The vulnerability affects all installations running the vulnerable versions until they are updated to 3.0.8 or later.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.