VYPR

All 404 Redirect To Homepage

by Clogica

CVEs (2)

  • CVE-2021-24324MedMay 17, 2021
    risk 0.42cvss 6.5epss 0.01

    The 404 SEO Redirection WordPress plugin through 1.3 is lacking CSRF checks in all its settings, allowing attackers to make a logged in user change the plugin's settings. Due to the lack of sanitisation and escaping in some fields, it could also lead to Stored Cross-Site…

  • CVE-2021-24326MedMay 17, 2021
    risk 0.35cvss 5.4epss 0.01

    The tab parameter of the settings page of the All 404 Redirect to Homepage WordPress plugin before 1.21 was vulnerable to an authenticated reflected Cross-Site Scripting (XSS) issue as user input was not properly sanitised before being output in an attribute.