CVE · Medium

CVE-2022-40695 — SEO Redirection Plugin – 301 Redirect Manager [seo-redirection] < 9.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-40695 SEO Redirection Plugin – 301 Redirect Manager [seo-redirection] < 9.1 Cross-Site Request Forgery (CSRF) Medium 5.4 < 9.1 9.1 2022-10-25

CVE-2022-40695

The SEO Redirection Plugin (301 Redirect Manager) up to version 8.9 contains a cross-site request forgery vulnerability stemming from inadequate nonce checks in the option_page_history.php and option_page_404.php files. An attacker could exploit this flaw by crafting malicious requests that, if clicked by an authenticated administrator, would allow unauthorized modification of 404 page configuration and redirection history records. The vulnerability requires social engineering to succeed, as the administrator must be tricked into accessing the attacker's link while logged in to WordPress.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.