VYPR

SEO Redirection Plugin – 301 Redirect Manager

by WordPress

CVEs (2)

  • CVE-2021-24847HigNov 17, 2021
    risk 0.57cvss 8.8epss 0.01

    The importFromRedirection AJAX action of the SEO Redirection Plugin – 301 Redirect Manager WordPress plugin before 8.2, available to any authenticated user, does not properly sanitise the offset parameter before using it in a SQL statement, leading an SQL injection when the…

  • CVE-2021-24187MedApr 5, 2021
    risk 0.35cvss 5.4epss 0.01

    The setting page of the SEO Redirection Plugin - 301 Redirect Manager WordPress plugin before 6.4 is vulnerable to reflected Cross-Site Scripting (XSS) as user input is not properly sanitised before being output in an attribute.