Add to Cart Custom Redirect for WooCommerce
Add to Cart Custom Redirect for WooCommerce has one disclosed vulnerability in the WordSec catalog, all reported in 2024; it is fixed as of September 2026. Their average CVSS score is 8.1, and the most serious one scores 8.1 out of 10. Severity breakdown: 0 critical and 1 high.
The most common weakness is Missing Authorization, behind 1 of the records (100%).
The one issue recorded for Add to Cart Custom Redirect for WooCommerce has a vendor fix available, so running the current release closes it.
All of these findings were reported by Lucio Sá. Add to Cart Custom Redirect for WooCommerce is installed on roughly 2,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.
CVE-2024-1862WooCommerce Add to Cart Custom Redirect <= 1.2.13 - Authenticated(Contributor+) Missing Authorization to Limited Arbitrary Options Update
Read the full analysisVulnerability Records
Add to Cart Custom Redirect for WooCommerce
Author
ForwardFlip
This plugin adds a field to the Edit Product page (under the General product info) that accepts a URL from the administrator or shop manager. When this field is set, the front-end user (customer) will be redirected to the URL when that product is added to the cart. This can be useful if you want to automatically prompt your customers to purchase other products. Upgrade to Custom Redirects for WooCommerce With the premium version of Custom Redirects for WooCommerce, you get access to: Add-to-cart redirects when your customers add products to their cart After-purchase redirects when your customers complete checkout Open redirects in new tabs Redirects for product variations Product-specific Redirect URLs Product Category/Tag Redirects Redirect on AJAX Add-to-Cart Support for Product CSV Import/Export (import and export redirects) Convenient admin page to see all your redirects Seamless upgrade from the Free version to Premium One Year of Updates & Premium Support Learn more about Custom Redirects for WooCommerce
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C