First published: Mon Nov 28 2011(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in (1) view/admin/log_item.php and (2) view/admin/log_item_details.php in the Redirection plugin 2.2.9 for WordPress allow remote attackers to inject arbitrary web script or HTML via the Referer HTTP header in a request to a post that does not exist.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
John Godley Redirection Plugin | =2.2.9 | |
WordPress | ||
All of | ||
John Godley Redirection Plugin | =2.2.9 | |
WordPress |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-4562 is classified as a moderate severity vulnerability due to its potential to enable cross-site scripting attacks.
To fix CVE-2011-4562, upgrade the Redirection plugin to version 2.2.10 or later.
CVE-2011-4562 affects the Redirection plugin version 2.2.9 for WordPress, specifically in view/admin/log_item.php and view/admin/log_item_details.php.
Yes, CVE-2011-4562 can be exploited remotely by injecting malicious scripts via the Referer HTTP header.
No, only version 2.2.9 of the Redirection plugin is vulnerable to CVE-2011-4562; subsequent versions are patched.