6.5
CVE-2023-1331
- EPSS 0.33%
- Veröffentlicht 17.04.2023 13:15:38
- Zuletzt bearbeitet 06.02.2025 17:15:15
- Quelle contact@wpscan.com
- CVE-Watchlists
- Unerledigt
Redirection < 1.1.5 - Plugin Reset via CSRF
Redirection <= 1.1.4 - Cross-Site Request Forgery to Plugin Reset
The Redirection WordPress plugin before 1.1.5 does not have CSRF checks in the uninstall action, which could allow attackers to make logged in admins delete all the redirections through a CSRF attack.
Mögliche Gegenmaßnahme
Redirection: Update to version 1.1.5, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Inisev ≫ Redirection SwPlatformwordpress Version < 1.1.5
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
Redirection
Version
*-1.1.4
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.33% | 0.241 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
|
https://wpscan.com/vulnerability/f81d9340-cf7e-46c4-b669-e61f2559cb8c
https://www.wordfence.com/threat-intel/vulnerabilities/id/18a41bef-feed-4096-a1f4-9c99caac6ce9