Plugin Vulnerability Hub
Plugin 27 known issues Latest disclosed Mar 21, 2023

Redirection Vulnerabilities

Review known vulnerability records for the WordPress plugin Redirection (`redirect-redirection`), including severity, CVE references, affected versions, and patch status.

Recent tracked CVEs on this page include CVE-2023-1331, so operators can jump from disclosure to patch validation without scanning the full feed first.

Known Records
27
High or Critical
0
Patch Coverage
100%
Last Updated
Jan 22, 2024
Priority CVE Quick Links

Fast paths into Redirection CVE reports

Start with the highest-signal CVE records for this WordPress plugin before scanning the full vulnerability feed.

Indexed CVEs
2
Coverage Snapshot

What this page helps you verify fast

This hub clusters every indexed record for Redirection so operators can confirm whether a disclosed issue maps to the installed slug, version range, and patch path.

Patch Visibility
27 records include a published patch path, leaving 0 with no listed safe release yet.
Severity Mix
0 critical and 0 high severity findings.
Recent CVEs
CVE-2023-1331
Reference Workflow
Jump from the hub into the full report when you need remediation notes, exploit context, CVSS vectors, or source references.
Triage First

Open the records most likely to drive action

These recent records surface the CVE strings, patch cues, and direct report links most operators need first.

Known Vulnerabilities

Reports for Redirection

Sorted by latest disclosure date so newly published issues surface first.

Plugin Medium Patched: Yes CVE-2023-1331
CVE-2023-1331: Redirection <= 1.1.4 - Cross-Site Request Forgery to Plugin Reset

The Redirection plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.4. This is due to missing or incorrect nonce validation on the 'uninstall' function hooked via admin_post. This makes it possible for unauthenticated attackers t...

Published
Mar 21, 2023
Patched Release
1.1.5
Affected Versions
Versions up to 1.1.4
Next Step
Update to 1.1.5 or newer if supported.
Plugin Medium Patched: Yes
Redirect Redirection <= 1.1.4 - Cross-Site Request Forgery to Plugin De-Installation

The Redirect Redirection plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.4. This is due to missing nonce validation on the uninstall() function called via an admin_post hook. This makes it possible for unauthenticated attacke...

Published
Mar 14, 2023
Patched Release
1.1.5
Affected Versions
Versions up to 1.1.4
Next Step
Update to 1.1.5 or newer if supported.
Plugin Medium Patched: Yes
Redirect Redirection <= 1.1.3 - Missing Authorization in 'LoadTab' function

The Redirect Redirection plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the LoadTab function called via an AJAX action in versions up to, and including, 1.1.3. This makes it possible for authenticated attackers with subscrib...

Published
Feb 22, 2023
Patched Release
1.1.4
Affected Versions
Versions up to 1.1.3
Next Step
Update to 1.1.4 or newer if supported.
Plugin Medium Patched: Yes CVE-2023-1330
CVE-2023-1330: Redirect Redirection <= 1.1.3 - Cross-Site Request Forgery via 'addRedirect' function

The Redirect Redirection plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3. This is due to missing or incorrect nonce validation on the addRedirect function. This makes it possible for unauthenticated attackers to add redirec...

Published
Feb 22, 2023
Patched Release
1.1.4
Affected Versions
Versions up to 1.1.3
Next Step
Update to 1.1.4 or newer if supported.
Plugin Medium Patched: Yes
Redirect Redirection <= 1.1.3 - Missing Authorization in 'SaveSettings' function

The Redirect Redirection plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the SaveSettings function called via an AJAX action in versions up to, and including, 1.1.3. This makes it possible for authenticated attackers wi...

Published
Feb 21, 2023
Patched Release
1.1.4
Affected Versions
Versions up to 1.1.3
Next Step
Update to 1.1.4 or newer if supported.
Plugin Medium Patched: Yes
Redirect Redirection <= 1.1.3 - Cross-Site Request Forgery via 'deleteRedirect' function

The Redirect Redirection plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3. This is due to missing or incorrect nonce validation on the deleteRedirect function. This makes it possible for unauthenticated attackers to delete r...

Published
Feb 21, 2023
Patched Release
1.1.4
Affected Versions
Versions up to 1.1.3
Next Step
Update to 1.1.4 or newer if supported.
Plugin Medium Patched: Yes
Redirect Redirection <= 1.1.3 - Cross-Site Request Forgery via 'SaveSettings' function

The Redirect Redirection plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3. This is due to missing or incorrect nonce validation on the SaveSettings function. This makes it possible for unauthenticated attackers to update the...

Published
Feb 21, 2023
Patched Release
1.1.4
Affected Versions
Versions up to 1.1.3
Next Step
Update to 1.1.4 or newer if supported.
Plugin Medium Patched: Yes
Redirect Redirection <= 1.1.3 - Missing Authorization in 'selectAll' function

The Redirect Redirection plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the selectAll function in versions up to, and including, 1.1.3. This makes it possible for authenticated attackers with subscriber-level access, and abo...

Published
Feb 21, 2023
Patched Release
1.1.4
Affected Versions
Versions up to 1.1.3
Next Step
Update to 1.1.4 or newer if supported.
Plugin Medium Patched: Yes
Redirect Redirection <= 1.1.3 - Missing Authorization in 'addRedirect' function

The Redirect Redirection plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the addRedirect function called via an AJAX action in versions up to, and including, 1.1.3. This makes it possible for authenticated attackers wit...

Published
Feb 21, 2023
Patched Release
1.1.4
Affected Versions
Versions up to 1.1.3
Next Step
Update to 1.1.4 or newer if supported.
Plugin Medium Patched: Yes
Redirect Redirection <= 1.1.3 - Cross-Site Request Forgery via 'cronLogDeleteOption' function

The Redirect Redirection plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3. This is due to missing or incorrect nonce validation on the cronLogDeleteOption function. This makes it possible for unauthenticated attackers to del...

Published
Feb 21, 2023
Patched Release
1.1.4
Affected Versions
Versions up to 1.1.3
Next Step
Update to 1.1.4 or newer if supported.
Plugin Medium Patched: Yes
Redirect Redirection <= 1.1.3 - Missing Authorization in 'instantEditRedirect' function

The Redirect Redirection plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the instantEditRedirect function called via an AJAX action in versions up to, and including, 1.1.3. This makes it possible for authenticated attac...

Published
Feb 21, 2023
Patched Release
1.1.4
Affected Versions
Versions up to 1.1.3
Next Step
Update to 1.1.4 or newer if supported.
Plugin Medium Patched: Yes
Redirect Redirection <= 1.1.3 - Missing Authorization in 'loadSettings' function

The Redirect Redirection plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the loadSettings function in versions up to, and including, 1.1.3. This makes it possible for authenticated attackers with subscriber-level access, and...

Published
Feb 21, 2023
Patched Release
1.1.4
Affected Versions
Versions up to 1.1.3
Next Step
Update to 1.1.4 or newer if supported.