CVE-2021-4338

The 404 to 301 plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on the open_redirect & save_redirect functions in versions up to, and including, 3.0.7. This makes it possible for authenticated attackers to view, create and edit redirections.
Configurations

Configuration 1 (hide)

cpe:2.3:a:duckdev:404_to_301:*:*:*:*:*:wordpress:*:*

History

No history.

Information

Published : 2023-06-07 02:15

Updated : 2023-11-07 03:40


NVD link : CVE-2021-4338

Mitre link : CVE-2021-4338

CVE.ORG link : CVE-2021-4338


JSON object : View

Products Affected

duckdev

  • 404_to_301
CWE
CWE-862

Missing Authorization