Description
The Redirection WordPress plugin before 1.1.5 does not have CSRF checks in the uninstall action, which could allow attackers to make logged in admins delete all the redirections through a CSRF attack.
Published: 2023-04-17
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-23589 The Redirection WordPress plugin before 1.1.5 does not have CSRF checks in the uninstall action, which could allow attackers to make logged in admins delete all the redirections through a CSRF attack.
History

Thu, 06 Feb 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Inisev Redirection
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2025-02-06T16:18:03.408Z

Reserved: 2023-03-10T17:04:12.408Z

Link: CVE-2023-1331

cve-icon Vulnrichment

Updated: 2024-08-02T05:40:59.887Z

cve-icon NVD

Status : Modified

Published: 2023-04-17T13:15:38.240

Modified: 2025-02-06T17:15:15.157

Link: CVE-2023-1331

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses

No weakness.