CVE-2021-24353: Simple 301 Redirects by BetterLinks - 2.0.0 – 2.0.3 - Unauthenticated Redirect Import
The importdata function of the Simple 301 Redirects by BetterLinks WordPress plugin before 2.0.4 had no capability or nonce checks making it possible for unauthenticated users to import a set of site redirects.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-24353?
CVE-2021-24353 is a vulnerability in the Simple 301 Redirects by BetterLinks WordPress plugin that allows unauthenticated users to import a set of site redirects without capability or nonce checks.
Is CVE-2021-24353 severe?
Yes, CVE-2021-24353 has a severity rating of 8.8 (high).
How does CVE-2021-24353 affect the Simple 301 Redirects plugin?
CVE-2021-24353 affects the import_data function of the Simple 301 Redirects by BetterLinks WordPress plugin before version 2.0.4.
How can unauthenticated users exploit CVE-2021-24353?
Unauthenticated users can exploit CVE-2021-24353 by importing a set of site redirects without capability or nonce checks.
Are there any fixes available for CVE-2021-24353?
Yes, the fix for CVE-2021-24353 is to update the Simple 301 Redirects plugin to version 2.0.4 or later.