CVE-2021-24356: Simple 301 Redirects by BetterLinks - 2.0.0 – 2.0.3 - Arbitrary Plugin Activation
In the Simple 301 Redirects by BetterLinks WordPress plugin before 2.0.4, a lack of capability checks and insufficient nonce check on the AJAX action, simple301redirects/admin/activateplugin, made it possible for authenticated users to activate arbitrary plugins installed on vulnerable sites.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-24356?
CVE-2021-24356 is a vulnerability in the Simple 301 Redirects by BetterLinks WordPress plugin before version 2.0.4.
What is the severity of CVE-2021-24356?
The severity of CVE-2021-24356 is high (8.8).
What does CVE-2021-24356 allow?
CVE-2021-24356 allows authenticated users to activate arbitrary plugins on vulnerable sites.
How can I fix CVE-2021-24356?
To fix CVE-2021-24356, update the Simple 301 Redirects by BetterLinks plugin to version 2.0.4 or later.
Where can I find more information about CVE-2021-24356?
More information about CVE-2021-24356 can be found at the following references: [Wordfence link](https://www.wordfence.com/blog/2021/05/severe-vulnerabilities-patched-in-simple-301-redirects-by-betterlinks-plugin/) and [WPScan link](https://wpscan.com/vulnerability/be356530-5e00-4f27-8177-b80f3c1ae6e8)