CVE · Medium

CVE-2023-1330 — Redirection [redirect-redirection] < 1.1.5

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-1330 Redirection [redirect-redirection] < 1.1.5 Cross-Site Request Forgery (CSRF) Medium 6.5 < 1.1.5 1.1.5 2023-02-22

CVE-2023-1330

The Redirect Redirection plugin through version 1.1.3 contains a Cross-Site Request Forgery vulnerability affecting its addRedirect function due to inadequate nonce verification. An unauthenticated attacker can exploit this flaw by crafting malicious requests that, if a site administrator is tricked into clicking a link, would allow the attacker to create redirects on the target site. The vulnerability has been addressed in version 1.1.5 and later.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.