Vulnerability Description
The 404 to 301 plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on the open_redirect & save_redirect functions in versions up to, and including, 3.0.7. This makes it possible for authenticated attackers to view, create and edit redirections.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Duckdev | 404 To 301 | <= 3.0.7 |
Related Weaknesses (CWE)
References
- https://blog.nintechnet.com/broken-access-control-vulnerability-fixed-in-wordpreExploit
- https://plugins.trac.wordpress.org/changeset/2546695/404-to-301Patch
- https://wpscan.com/vulnerability/9f147107-bc5a-4a01-9979-cd9e16061f12Third Party Advisory
- https://www.acunetix.com/vulnerabilities/web/wordpress-plugin-404-to-301-redirecThird Party Advisory
- https://www.wordfence.com/threat-intel/vulnerabilities/id/05d6b27f-b1e5-4bb8-b7dThird Party Advisory
- https://blog.nintechnet.com/broken-access-control-vulnerability-fixed-in-wordpreExploit
- https://plugins.trac.wordpress.org/changeset/2546695/404-to-301Patch
- https://wpscan.com/vulnerability/9f147107-bc5a-4a01-9979-cd9e16061f12Third Party Advisory
- https://www.acunetix.com/vulnerabilities/web/wordpress-plugin-404-to-301-redirecThird Party Advisory
- https://www.wordfence.com/threat-intel/vulnerabilities/id/05d6b27f-b1e5-4bb8-b7dThird Party Advisory
FAQ
What is CVE-2021-4338?
CVE-2021-4338 is a vulnerability with a CVSS score of 6.4 (MEDIUM). The 404 to 301 plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on the open_redirect & save_redirect functions in versions up to, and including, 3.0.7. This ...
How severe is CVE-2021-4338?
CVE-2021-4338 has been rated MEDIUM with a CVSS base score of 6.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-4338?
Check the references section above for vendor advisories and patch information. Affected products include: Duckdev 404 To 301.