CVE · Medium

CVE-2024-31435 — Redirection [redirect-redirection] < 1.2.0

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-31435 Redirection [redirect-redirection] < 1.2.0 Missing Authorization Medium 4.3 < 1.2.0 1.2.0 2024-04-10

CVE-2024-31435

The WordPress Redirect Redirection plugin before version 1.2.0 contains a broken access control vulnerability discovered by Dhabaleshwar Das that allows unauthorized users to perform privileged actions due to missing authorization, authentication, or nonce verification in certain functions. This flaw permits low-level users to execute operations normally restricted to higher-privileged accounts. The issue has been resolved in version 1.2.0 and later.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.