Unauthorized Access in SEO Redirection Plugin for WordPress
CVE-2026-13703
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 6 August 2026
Badges
What is CVE-2026-13703?
The SEO Redirection Plugin for WordPress, prior to version 9.19, contains a flaw that permits logged-in users, regardless of their privileges, to execute specific authenticated AJAX actions without proper capability checks. This vulnerability allows these users to gain access to sensitive configuration information, specifically the site’s 301 redirect rules, including both the source and destination URLs. This issue poses a risk of unintended information exposure, impacting the security and integrity of web redirections.
Affected Version(s)
SEO Redirection Plugin 0 < 9.19
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.