CVE-2021-24354: Simple 301 Redirects by BetterLinks - 2.0.0-2.0.3 - Arbitrary Plugin Installation
A lack of capability checks and insufficient nonce check on the AJAX action in the Simple 301 Redirects by BetterLinks WordPress plugin before 2.0.4, made it possible for authenticated users to install arbitrary plugins on vulnerable sites.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-24354?
CVE-2021-24354 is a vulnerability in the Simple 301 Redirects by BetterLinks WordPress plugin before version 2.0.4 that allows authenticated users to install arbitrary plugins on vulnerable sites.
How severe is CVE-2021-24354?
CVE-2021-24354 has a severity rating of 8.8 (high).
How does CVE-2021-24354 affect the Simple 301 Redirects plugin?
CVE-2021-24354 affects the Simple 301 Redirects by BetterLinks WordPress plugin before version 2.0.4.
How can I fix CVE-2021-24354?
To fix CVE-2021-24354, you should update the Simple 301 Redirects plugin to version 2.0.4 or later.
Where can I find more information about CVE-2021-24354?
You can find more information about CVE-2021-24354 at the following references: [Wordfence](https://www.wordfence.com/blog/2021/05/severe-vulnerabilities-patched-in-simple-301-redirects-by-betterlinks-plugin/) and [WPScan](https://wpscan.com/vulnerability/8638b36c-6641-491f-b9df-5db3645e4668).