PLUGIN SECURITY

Is Redirection safe?

Manage 301 redirects, track 404 errors, and improve your site. No knowledge of Apache or Nginx required.

What this plugin does

  • Slug: redirection
  • Author: John Godley
  • 2000000+ active installs
  • 88/100 rating (702 reviews on wordpress.org)
  • 76788190 all-time downloads
  • On WordPress.org since 2007-09-10

301404Apachehtaccessredirect

Maintenance status

  • Latest known version: 5.9.0
  • Last updated: 2026-07-11 12:51pm GMT
  • Tested up to WordPress: 7.0.4
  • Requires PHP: 7.4+
  • Max supported PHP (analyzed): 8.4

Known vulnerabilities

4 known CVEs on file for Redirection. Reported between 2011 and 2018.

CVE Vulnerability Type Severity Affected Fixed in Published Status
Redirection [redirection] < 3.6.4 Unknown < 3.6.4 3.6.4 2018-12-06 ✓ fixed in latest
Redirection [redirection] < 3.6.4 Unknown < 3.6.4 3.6.4 2018-11-14 ✓ fixed in latest
CVE-2018-1000504 Redirection [redirection] < 2.8 URL Redirection to Untrusted Site ('Open Redirect') High 7.2 < 2.8 2.8 2018-06-26 ✓ fixed in latest
Redirection [redirection] < 2.8 Unknown < 2.8 2.8 2018-06-20 ✓ fixed in latest
Redirection [redirection] < 2.3.4 Unknown < 2.3.4 2.3.4 2015-05-15 ✓ fixed in latest
Redirection [redirection] < 2.2.9 Unknown < 2.2.9 2.2.9 2015-05-15 ✓ fixed in latest
CVE-2011-5329 Redirection [redirection] < 2.2.9 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 2.2.9 2.2.9 2014-08-01 ✓ fixed in latest
CVE-2012-6717 Redirection [redirection] < 2.2.12 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 2.2.12 2.2.12 2012-05-04 ✓ fixed in latest
+ 7 more known vulnerabilities
CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2011-4562 Redirection [redirection] < 2.2.10 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Unknown < 2.2.10 2.2.10 2011-11-28 ✓ fixed in latest
Redirection [redirection] < 3.6.3 Unknown < 3.6.3 3.6.3 ✓ fixed in latest
Redirection [redirection] < 2.8 Unknown < 2.8 2.8 ✓ fixed in latest
Redirection [redirection] < 2.3.4 Unknown < 2.3.4 2.3.4 ✓ fixed in latest
Redirection 2.3.3 - view/admin/item.php URL Handling Reflected XSS Unknown < 2.3.4 2.3.4 ✓ fixed in latest
Redirection < 2.8 - Authenticated Local File Inclusion Unknown < 2.8 2.8 ✓ fixed in latest
Redirection <= 3.6.2 - Cross-Site Request Forgery (CSRF) Unknown < 3.6.3 3.6.3 ✓ fixed in latest

How to fix it

Keep Redirection updated — 5.9.0 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.