CVE-2021-24355 Information

Description

In the Simple 301 Redirects by BetterLinks WordPress plugin before 2.0.4 the lack of capability checks and insufficient nonce check on the AJAX actions simple301redirects/admin/get_wildcard and simple301redirects/admin/wildcard made it possible for authenticated users to retrieve and update the wildcard value for redirects.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Reference

https://wpscan.com/vulnerability/ce8f9648-30fb-4fb9-894e-879dc0f26f98 https://www.wordfence.com/blog/2021/05/severe-vulnerabilities-patched-in-simple-301-redirects-by-betterlinks-plugin/

Attack Complexity

LOW

Privileges Required

LOW

User Interaction Required

LOW

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

NONE

Availability Impact

LOW

Base Score

NONE

Base Severity

4.3

Share on: