First published: Mon Jun 14 2021(Updated: )
A lack of capability checks and insufficient nonce check on the AJAX action in the Simple 301 Redirects by BetterLinks WordPress plugin before 2.0.4, made it possible for authenticated users to install arbitrary plugins on vulnerable sites.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Wpdeveloper Simple 301 Redirects | >=2.0.0<2.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-24354 is a vulnerability in the Simple 301 Redirects by BetterLinks WordPress plugin before version 2.0.4 that allows authenticated users to install arbitrary plugins on vulnerable sites.
CVE-2021-24354 has a severity rating of 8.8 (high).
CVE-2021-24354 affects the Simple 301 Redirects by BetterLinks WordPress plugin before version 2.0.4.
To fix CVE-2021-24354, you should update the Simple 301 Redirects plugin to version 2.0.4 or later.
You can find more information about CVE-2021-24354 at the following references: [Wordfence](https://www.wordfence.com/blog/2021/05/severe-vulnerabilities-patched-in-simple-301-redirects-by-betterlinks-plugin/) and [WPScan](https://wpscan.com/vulnerability/8638b36c-6641-491f-b9df-5db3645e4668).