Authorization Bypass in 404 to 301 Redirects Plugin for WordPress
CVE-2021-4338
6.4MEDIUM
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 7 June 2023
What is CVE-2021-4338?
The 404 to 301 plugin for WordPress is susceptible to authorization bypass due to inadequate capability checks in the open_redirect and save_redirect functions. Authenticated attackers can exploit this vulnerability to create, edit, and view redirections without proper permissions, potentially leading to unauthorized access and manipulation of redirection paths.
Affected Version(s)
404 to 301 – Redirect, Log and Notify 404 Errors * <= 3.0.7