CVE-2023-1330
The Redirect Redirection plugin through version 1.1.3 contains a Cross-Site Request Forgery vulnerability affecting its addRedirect function due to inadequate nonce verification. An unauthenticated attacker can exploit this flaw by crafting malicious requests that, if a site administrator is tricked into clicking a link, would allow the attacker to create redirects on the target site. The vulnerability has been addressed in version 1.1.5 and later.
Based on public CVE data (MITRE/NVD).