SEO Redirection <= 6.4 - Authenticated Stored Cross-Site Scripting
2021-04-16 00:00
R3N0Strategic Overview
StatusPatched in 7.1
Affected PluginSEO Redirection Plugin – 301 Redirect Manager
Affected Version
<= 6.4CVSS4.8Medium
CVE
CVE-2021-24327Vulnerability Overview
The SEO Redirection Plugin – 301 Redirect Manager WordPress plugin before 7.1 did not sanitise the Redirect From and Redirect To fields when creating a new redirect in the dashboard, allowing high privilege users (even with the unfiltered_html disabled) to set XSS payloads
Technical Analysis
REMEDIATION: Update to version 7.1, or a newer patched version --- IDENTIFIER: CWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')) The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C