CVE · Medium

CVE-2022-38704 — SEO Redirection Plugin – 301 Redirect Manager [seo-redirection] < 9.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-38704 SEO Redirection Plugin – 301 Redirect Manager [seo-redirection] < 9.1 Cross-Site Request Forgery (CSRF) Medium 5.4 < 9.1 9.1 2022-08-01

CVE-2022-38704

The SEO Redirection Plugin – 301 Redirect Manager is susceptible to cross-site request forgery attacks in version 8.9 and earlier because the plugin fails to properly verify nonce tokens in its 404 error page and history page option files. An attacker could craft a malicious request to delete 404 redirects if they successfully deceive a site administrator into clicking a link, even though the attacker themselves lack direct access to the site. This vulnerability was remedied in version 9.1.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.