Unauthenticated SQL Injection in Advanced 301 and 302 Redirect Plugin by WordPress
CVE-2026-49067
9.3CRITICAL
What is CVE-2026-49067?
A vulnerability exists in the Advanced 301 and 302 Redirect plugin for WordPress, affecting versions up to 1.6.9. This issue allows attackers to exploit unauthenticated SQL injection, potentially compromising the application's database, manipulating data, or executing arbitrary SQL commands. Proper measures should be taken to update the plugin and secure the installation against unauthorized access.
Affected Version(s)
Advanced 301 and 302 Redirect <= 1.6.9