Stored XSS Vulnerability in SEO Redirection Plugin for WordPress
CVE-2016-10896

6.1MEDIUM

Key Information:

Vendor

Wordpress

Vendor
CVE Published:
21 August 2019

What is CVE-2016-10896?

The SEO Redirection Plugin for WordPress, prior to version 4.3, contains a stored Cross-Site Scripting (XSS) vulnerability that can allow attackers to inject malicious scripts into the user interface. This can lead to unauthorized actions being executed on behalf of users, potentially compromising sensitive data and user sessions. Website administrators using affected versions are encouraged to upgrade to mitigate the risks associated with this security flaw. For further details, check the official plugin page.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.