PT-2021-15688 · WordPress · 301 Redirects - Easy Redirect Manager

Nguyen Van Khanh

·

Published

2021-03-18

·

Updated

2023-05-18

·

CVE-2021-24142

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: 301 Redirects - Easy Redirect Manager WordPress plugin versions prior to 2.51
Description: The issue arises from unvalidated input in the 301 Redirects - Easy Redirect Manager WordPress plugin. Specifically, versions before 2.51 did not sanitize the Redirect From column when importing a CSV file. This oversight allows high privilege users to perform SQL injections.
Recommendations: For versions prior to 2.51, update to version 2.51 or later to resolve the issue. As a temporary workaround, consider restricting the import of CSV files or sanitizing the Redirect From column manually until a patch is applied. Avoid using the Redirect From column in the affected plugin until the issue is resolved.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2021-24142

Affected Products

301 Redirects - Easy Redirect Manager