CVE-2026-13703: SEO Redirection Plugin – 301 Redirect Manager < 9.19 - Subscriber+ Redirect Rule Disclosure
The SEO Redirection Plugin WordPress plugin before 9.19 does not perform a capability check in one of its authenticated AJAX actions, allowing any logged-in user such as a subscriber to read the site's configured 301 redirect rules, including their source and destination URLs.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress plugin: SEO Redirection Plugin – 301 Redirect Managerto a version that resolves this vulnerability.Fixed in 9.19
Event History
Frequently Asked Questions
What is the severity of CVE-2026-13703?
CVE-2026-13703 has a risk score of 23, indicating a significant security concern.
How do I fix CVE-2026-13703?
To fix CVE-2026-13703, update the SEO Redirection Plugin to version 9.19 or later.
Who is affected by CVE-2026-13703?
CVE-2026-13703 affects any WordPress sites using the SEO Redirection Plugin before version 9.19.
What kind of information can be exposed due to CVE-2026-13703?
CVE-2026-13703 allows logged-in users, such as subscribers, to view the site's 301 redirect rules, including source and destination URLs.
Is any user role affected by CVE-2026-13703?
Yes, even users with the subscriber role can exploit CVE-2026-13703 to access sensitive redirect information.