CVE-2021-24355 Information
Jun 07, 2022
cve
Description
In the Simple 301 Redirects by BetterLinks WordPress plugin before 2.0.4 the lack of capability checks and insufficient nonce check on the AJAX actions simple301redirects/admin/get_wildcard and simple301redirects/admin/wildcard made it possible for authenticated users to retrieve and update the wildcard value for redirects.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Reference
https://wpscan.com/vulnerability/ce8f9648-30fb-4fb9-894e-879dc0f26f98 https://www.wordfence.com/blog/2021/05/severe-vulnerabilities-patched-in-simple-301-redirects-by-betterlinks-plugin/
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
NONE
Availability Impact
LOW
Base Score
NONE
Base Severity
4.3
Share on: