First published: Fri Aug 30 2019(Updated: )
The simple-301-redirects-addon-bulk-uploader plugin through 1.2.4 for WordPress has no requirement for authentication for action=bulk301export or action=bulk301clearlist.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Webcraftic Simple 301 Redirects | <=1.2.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-15818 is considered a high severity vulnerability due to the lack of authentication for certain actions in the plugin.
To fix CVE-2019-15818, update the Simple 301 Redirects Addon Bulk Uploader plugin to version 1.2.5 or later.
CVE-2019-15818 can allow unauthorized users to perform bulk export and clear operations on redirects, potentially leading to data leakage or manipulation.
CVE-2019-15818 affects versions of the Simple 301 Redirects Addon Bulk Uploader plugin up to and including 1.2.4.
No, actions like bulk301export and bulk301clearlist in CVE-2019-15818 do not require authentication, making them vulnerable.