CVE-2023-1331: Redirection < 1.1.5 - Plugin Reset via CSRF
Published Apr 17, 2023
·Updated
The Redirection WordPress plugin before 1.1.5 does not have CSRF checks in the uninstall action, which could allow attackers to make logged in admins delete all the redirections through a CSRF attack.
Affected Software
1 affected component
Inisev Redirection Wordpress<1.1.5
Event History
Apr 17, 2023
CVE Published
via MITRE·12:17 PM
Data Sourced
via MITRE·12:17 PM
DescriptionWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for the Redirection WordPress plugin?
The vulnerability ID for the Redirection WordPress plugin is CVE-2023-1331.
2
What is the severity of CVE-2023-1331?
The severity of CVE-2023-1331 is medium (6.5).
3
What is the affected software by CVE-2023-1331?
The affected software by CVE-2023-1331 is the Redirection WordPress plugin version up to 1.1.5.
4
What is the CWE number for CVE-2023-1331?
The CWE number for CVE-2023-1331 is 352.
5
How can an attacker exploit CVE-2023-1331?
An attacker can exploit CVE-2023-1331 by performing a CSRF attack to make logged in admins delete all the redirections.