PT-2025-2164 · WordPress · Seo Blogger To Wordpress Migration Using 301 Redirection

Colin Xu

·

Published

2025-01-23

·

Updated

2025-01-23

·

CVE-2024-13422

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions SEO Blogger to WordPress Migration using 301 Redirection plugin for WordPress versions up to, and including, 0.4.8
Description The issue is related to Reflected Cross-Site Scripting via the url parameter due to insufficient input sanitization and output escaping. This allows unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Recommendations For versions up to, and including, 0.4.8, update to a version that addresses the insufficient input sanitization and output escaping issue. As a temporary workaround, consider restricting access to the url parameter in the affected plugin until a patch is available. Avoid using the url parameter in the affected plugin until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-13422

Affected Products

Seo Blogger To Wordpress Migration Using 301 Redirection