CVE-2019-15818: Medium severity webcraftic simple 301 redirects vulnerability
The simple-301-redirects-addon-bulk-uploader plugin through 1.2.4 for WordPress has no requirement for authentication for action=bulk301export or action=bulk301clearlist.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-15818?
CVE-2019-15818 is considered a high severity vulnerability due to the lack of authentication for certain actions in the plugin.
How do I fix CVE-2019-15818?
To fix CVE-2019-15818, update the Simple 301 Redirects Addon Bulk Uploader plugin to version 1.2.5 or later.
What are the potential impacts of CVE-2019-15818?
CVE-2019-15818 can allow unauthorized users to perform bulk export and clear operations on redirects, potentially leading to data leakage or manipulation.
Which versions are affected by CVE-2019-15818?
CVE-2019-15818 affects versions of the Simple 301 Redirects Addon Bulk Uploader plugin up to and including 1.2.4.
Is authentication required for actions impacted by CVE-2019-15818?
No, actions like bulk301export and bulk301clearlist in CVE-2019-15818 do not require authentication, making them vulnerable.