Vulnerability Description
The Redirection WordPress plugin before 1.1.5 does not have CSRF checks in the uninstall action, which could allow attackers to make logged in admins delete all the redirections through a CSRF attack.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Inisev | Redirection | < 1.1.5 |
References
- https://wpscan.com/vulnerability/f81d9340-cf7e-46c4-b669-e61f2559cb8cExploitThird Party Advisory
- https://wpscan.com/vulnerability/f81d9340-cf7e-46c4-b669-e61f2559cb8cExploitThird Party Advisory
FAQ
What is CVE-2023-1331?
CVE-2023-1331 is a vulnerability with a CVSS score of 6.5 (MEDIUM). The Redirection WordPress plugin before 1.1.5 does not have CSRF checks in the uninstall action, which could allow attackers to make logged in admins delete all the redirections through a CSRF attack.
How severe is CVE-2023-1331?
CVE-2023-1331 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-1331?
Check the references section above for vendor advisories and patch information. Affected products include: Inisev Redirection.