First published: Mon Jun 14 2021(Updated: )
In the Simple 301 Redirects by BetterLinks WordPress plugin before 2.0.4, the lack of capability checks and insufficient nonce check on the AJAX actions, simple301redirects/admin/get_wildcard and simple301redirects/admin/wildcard, made it possible for authenticated users to retrieve and update the wildcard value for redirects.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Wpdeveloper Simple 301 Redirects | >=2.0.0<2.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-24355 refers to a vulnerability in the Simple 301 Redirects by BetterLinks WordPress plugin before version 2.0.4.
The severity of CVE-2021-24355 is medium with a severity value of 4.3.
The Simple 301 Redirects by BetterLinks WordPress plugin versions before 2.0.4 are affected by CVE-2021-24355.
An authenticated user can exploit CVE-2021-24355 by retrieving and updating the wildcard in the plugin's AJAX actions.
You can find more information about CVE-2021-24355 at the following references: [Reference 1](https://wpscan.com/vulnerability/ce8f9648-30fb-4fb9-894e-879dc0f26f98), [Reference 2](https://www.wordfence.com/blog/2021/05/severe-vulnerabilities-patched-in-simple-301-redirects-by-betterlinks-plugin/).