CVE-2022-40695
The SEO Redirection Plugin (301 Redirect Manager) up to version 8.9 contains a cross-site request forgery vulnerability stemming from inadequate nonce checks in the option_page_history.php and option_page_404.php files. An attacker could exploit this flaw by crafting malicious requests that, if clicked by an authenticated administrator, would allow unauthorized modification of 404 page configuration and redirection history records. The vulnerability requires social engineering to succeed, as the administrator must be tricked into accessing the attacker's link while logged in to WordPress.
Based on public CVE data (MITRE/NVD).