WordPress SEO Redirection Plugin plugin <= 8.9 - Multiple Cross-Site Scripting (CSRF) vulnerabilities
Description
Multiple Cross-Site Scripting (CSRF) vulnerabilities in SEO Redirection Plugin plugin <= 8.9 on WordPress.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
CSRF vulnerabilities in SEO Redirection Plugin <= 8.9 allow attackers to perform unauthorized actions via crafted requests.
Vulnerability
Multiple Cross-Site Request Forgery (CSRF) vulnerabilities exist in the SEO Redirection Plugin – 301 Redirect Manager for WordPress, affecting versions 8.9 and earlier [1]. The plugin fails to properly validate or sanitize requests, allowing an attacker to trick an authenticated administrator into executing unwanted actions without their consent.
Exploitation
An attacker can craft a malicious link or webpage that, when visited by a logged-in WordPress administrator, triggers a forged request to the vulnerable plugin. The attack requires no direct network access to the server but relies on social engineering to lure the administrator into clicking the crafted link while authenticated. The CSRF token verification is missing or insufficient.
Impact
Successful exploitation enables an attacker to perform any action the administrator is authorized to do within the plugin, such as modifying redirect rules, deleting settings, or changing configuration. This can lead to redirection of site traffic to malicious sites, SEO manipulation, or disruption of normal site operation. The impact is limited to actions available within the plugin's admin interface [1].
Mitigation
The vendor released version 9.17 which updates the plugin and presumably addresses these vulnerabilities [1]. Users should upgrade to the latest version immediately. There are no known workarounds for older versions; updating is the recommended mitigation.
AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: <=8.9
- WP-buy/SEO Redirection Plugin – 301 Redirect Manager (WordPress plugin)v5Range: <= 8.9
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
0No linked articles in our index yet.