CVE-2019-15818
MEDIUMsimple-301-redirects-addon-bulk-uploader < 1.2.4 - Open Redirect via bulk301export or bulk301clearlist
Title source: llmDescription
The simple-301-redirects-addon-bulk-uploader plugin through 1.2.4 for WordPress has no requirement for authentication for action=bulk301export or action=bulk301clearlist.
References (3)
Core 3
Core References
Third Party Advisory x_refsource_misc
https://wpvulndb.com/vulnerabilities/9503
Product, Third Party Advisory x_refsource_misc
https://wordpress.org/plugins/simple-301-redirects-addon-bulk-uploader/#developers
Exploit, Third Party Advisory x_refsource_misc
https://blog.nintechnet.com/unauthenticated-option-changes-in-wordpress-simple-301-redirects-addon-bulk-uploader-plugin/
Scores
CVSS v3
6.1
EPSS
0.0147
EPSS Percentile
70.3%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-601
Status
published
Products (1)
webcraftic/simple_301_redirects
< 1.2.4
Published
Aug 30, 2019
Tracked Since
Feb 18, 2026