CVE-2021-24355: Simple 301 Redirects by BetterLinks - 2.0.0 – 2.0.3 - Update and Retrieve Wildcard Value
In the Simple 301 Redirects by BetterLinks WordPress plugin before 2.0.4, the lack of capability checks and insufficient nonce check on the AJAX actions, simple301redirects/admin/getwildcard and simple301redirects/admin/wildcard, made it possible for authenticated users to retrieve and update the wildcard value for redirects.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-24355?
CVE-2021-24355 refers to a vulnerability in the Simple 301 Redirects by BetterLinks WordPress plugin before version 2.0.4.
What is the severity of CVE-2021-24355?
The severity of CVE-2021-24355 is medium with a severity value of 4.3.
What is affected by CVE-2021-24355?
The Simple 301 Redirects by BetterLinks WordPress plugin versions before 2.0.4 are affected by CVE-2021-24355.
How can an authenticated user exploit CVE-2021-24355?
An authenticated user can exploit CVE-2021-24355 by retrieving and updating the wildcard in the plugin's AJAX actions.
Where can I find more information about CVE-2021-24355?
You can find more information about CVE-2021-24355 at the following references: [Reference 1](https://wpscan.com/vulnerability/ce8f9648-30fb-4fb9-894e-879dc0f26f98), [Reference 2](https://www.wordfence.com/blog/2021/05/severe-vulnerabilities-patched-in-simple-301-redirects-by-betterlinks-plugin/).