Redirect 404 to parent

Redirect 404 to parent has one disclosed vulnerability in the WordSec catalog, all reported in 2021; it is fixed as of September 2026. Their average CVSS score is 6.1, and the most serious one scores 6.1 out of 10.

The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).

The one issue recorded for Redirect 404 to parent has a vendor fix available, so running the current release closes it.

All of these findings were reported by 0xB9. Redirect 404 to parent is installed on roughly 60 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.

Strategic Overview

Avg CVSSMedium
6.1/ 10
Patch Coverage100%
Open

0

Fixed

1

Get automatic notifications for all Redirect 404 to parent vulnerabilities before they are exploited.

Highest severity on recordCVSS 6.1CVE-2021-24286

Redirect 404 to parent < 1.3.1 - Reflected Cross-Site Scripting

Read the full analysis

Vulnerability Records

1 records
Redirect 404 to parent banner
Latestv1.4.1

Redirect 404 to parent

Moove Agency

Author

Moove Agency

4.5(2)
90/100
Last Updated
2026-05-26 (4mo ago)
Active Installs
60+
Downloads
6,785
Requires WP
4.3+
Requires PHP
5.6+
Tested up to
WP 7.0.4
Created
2016-03-01 (11y ago)

Redirect any 404 request to the parent URL with this incredibly powerful, easy-to-use, well supported and 100% free WordPress cookie plugin. Simply put, the plugin performs the following: when there is a 404 page found such as /about/sample-url then the plugin will automatically redirect the visitor to /about/ It’s a very powerful plugin that saves you many hours specifying individual redirects for every 404 page. With our plugin, you can define one simple rule that will cover all child pages that produce 404 errors. Features You can defined the BASE URL – this is the URL that will be served as a starting point. You can define the type of the redirection done by WordPress (302, 301, etc.). You can add as many rules you want and easily delete them if you don’t need them anymore The plugin checks if you already added a rule based on the slug, so you won’t add the same rule twice. The plugin checks if the URL you are setting up as a BASE exists in WordPress as a post or page, so you’re not creating an erroneous URL base. You can see a log of the 404 redirected by the plugin (if the plugin registers any 404 errors), so you can easily identify what URLs are generating the 404 errors. If there are more than 10 rows in the 404 log/statistics, you can download the whole log for an URL in CSV format. Example Use Case Base URL (set up in this plugin as a rule): http://yourdomain.com/sample-page/ Target URL: http://yourdomain.com/sample-page/non-existing-page In this case if a visitor tries to access the TARGET URL, WordPress returns a 404 error/page by default because the page/post doesn’t exist. Our plugin will automatically redirect the visitor to http://yourdomain.com/sample-page/ instead of letting the visitor end up on a 404 page. About us Moove Agency is a premium supplier of quality WordPress plugins, services and support. Visit our site to learn more.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C