Unauthenticated SQL Injection in Advanced 301 and 302 Redirect Plugin by WordPress
CVE-2026-49067

9.3CRITICAL

Key Information:

Vendor

WordPress

Vendor
CVE Published:
15 June 2026

What is CVE-2026-49067?

A vulnerability exists in the Advanced 301 and 302 Redirect plugin for WordPress, affecting versions up to 1.6.9. This issue allows attackers to exploit unauthenticated SQL injection, potentially compromising the application's database, manipulating data, or executing arbitrary SQL commands. Proper measures should be taken to update the plugin and secure the installation against unauthorized access.

Affected Version(s)

Advanced 301 and 302 Redirect <= 1.6.9

References

CVSS V3.1

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

dodoh4t | Patchstack Bug Bounty Program
.