{"error":0,"message":null,"data":{"name":"Redirection","plugin":"redirection","link":"https:\/\/wordpress.org\/plugins\/redirection\/","latest":"1789825500","closed":0,"closed_reason":null,"closed_date":null,"vulnerability":[{"uuid":"79cff879592d05522c3e4377d5efd693c526bc76e11fff1e8d872ab7eebc9162","name":"Redirection [redirection] < 2.2.12","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.2.12","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2012-6717","name":"CVE-2012-6717","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2012-6717","description":"[en] The redirection plugin before 2.2.12 for WordPress has XSS, a different issue than CVE-2011-4562.","date":"2019-08-28"},{"id":"7358bdfc40fb0a2aa35289920f1ecb71a461e144","name":"Redirection < 2.2.12 - Reflected Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/redirection\/redirection-2212-reflected-cross-site-scripting","description":"The redirection plugin before 2.2.12 for WordPress has XSS, a different issue than CVE-2011-4562.","date":"2012-05-04"},{"id":"c3884cbf-b63a-4075-b7a8-2777f50bd3a9","name":"Redirection &lt; 2.2.12 - XSS","link":"https:\/\/wpscan.com\/vulnerability\/c3884cbf-b63a-4075-b7a8-2777f50bd3a9","description":"The Redirection WordPress plugin was affected by a XSS security vulnerability.","date":null}],"impact":{"cvss":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"8fc1434690a8be31fb11d51df605033c9b6ffc23b23986a5d1b2860a1b719cab","name":"Redirection [redirection] < 2.2.9","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.2.9","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2011-5329","name":"CVE-2011-5329","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2011-5329","description":"[en] The redirection plugin before 2.2.9 for WordPress has XSS in the admin menu, a different issue than CVE-2011-4562.","date":"2019-08-28"},{"id":"eb8bc0f8727fac2a20767493e8a3c033cf4576fd","name":"Redirection <= 2.2.8 - Reflected Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/redirection\/redirection-228-reflected-cross-site-scripting","description":"The redirection plugin before 2.2.9 for WordPress has XSS in the admin menu, a different issue than CVE-2011-4562.","date":"2014-08-01"},{"id":"b5c4e33c-d0c2-4fc1-bad7-aa7e7a81f0fa","name":"Redirection - wp-admin\/tools.php id Parameter XSS","link":"https:\/\/wpscan.com\/vulnerability\/b5c4e33c-d0c2-4fc1-bad7-aa7e7a81f0fa","description":"The Redirection WordPress plugin was affected by a wp-admin\/tools.php id Parameter XSS security vulnerability.","date":null}],"impact":{"cvss":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"c93e993cd6a63e666e4c1db78910f2b5f8f545d10e0d5d37ebfa193894b75fc2","name":"Redirection [redirection] < 2.2.10","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.2.10","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2011-4562","name":"CVE-2011-4562","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2011-4562","description":"[en] Multiple cross-site scripting (XSS) vulnerabilities in (1) view\/admin\/log_item.php and (2) view\/admin\/log_item_details.php in the Redirection plugin 2.2.9 for WordPress allow remote attackers to inject arbitrary web script or HTML via the Referer HTTP header in a request to a post that does not exist.","date":"2011-11-28"},{"id":"088baf9b4be5487f97ef6b3c27a49839e4932d3a","name":"WordPress Redirection Plugin <= 2.2.9 - Multiple XSS","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/redirection\/vulnerability\/wordpress-redirection-plugin-2-2-9-multiple-xss","description":"Because of these vulnerabilities, the attackers can inject arbitrary web script or HTML via the Referer HTTP header in a request to a post that does not exist.\nUpdate the plugin.","date":"2011-11-28"},{"id":"596def66c350e3049f20f27b396a5c38776359da","name":"Redirection <= 2.2.9 - Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/redirection\/redirection-229-cross-site-scripting","description":"Multiple cross-site scripting (XSS) vulnerabilities in (1) view\/admin\/log_item.php and (2) view\/admin\/log_item_details.php in the Redirection plugin 2.2.9 for WordPress allow remote attackers to inject arbitrary web script or HTML via the Referer HTTP header in a request to a post that does not exist.","date":"2014-08-01"},{"id":"de57180a-b276-4f00-a0df-dc9d731d88bd","name":"Redirection - view\/admin\/log_item.php Non-existent Posts Referer HTTP Header XSS","link":"https:\/\/wpscan.com\/vulnerability\/de57180a-b276-4f00-a0df-dc9d731d88bd","description":"The Redirection WordPress plugin was affected by a view\/admin\/log_item.php Non-existent Posts Referer HTTP Header XSS security vulnerability.","date":null}],"impact":{"cvss":{"version":null,"vector":null,"av":null,"ac":null,"pr":null,"ui":null,"s":null,"c":null,"i":null,"a":null,"score":"0.0","severity":null,"exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"c76079ebced517cff7928765e7a4ba2d49aae6ac3d9b005fe41c8f52c306705a","name":"Redirection [redirection] < 3.6.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.6.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"bbcb7273b0760b3fdf616079d66a84a33f2e2267","name":"WordPress Redirection plugin <= 3.6.2 - Cross-Site Request Forgery (CSRF) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/redirection\/vulnerability\/wordpress-redirection-plugin-3-6-2-cross-site-request-forgery-csrf-vulnerability","description":"Cross-Site Request Forgery (CSRF) vulnerability found in WordPress Redirection plugin (versions <= 3.6.2).","date":"2018-12-06"}],"impact":[]},{"uuid":"367f190b74039f058ba1c26eebff597eae438dbea9aa4fe6d462859a313c811d","name":"Redirection [redirection] < 2.8","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.8","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"ed28059c3e85d71b9f5331feed22f8a56e9355ee","name":"WordPress Redirection plugin <= 2.7.3 - Authenticated Local File Inclusion vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/redirection\/vulnerability\/wordpress-redirection-plugin-2-7-3-authenticated-local-file-inclusion-vulnerability","description":"Authenticated Local File Inclusion vulnerability found by Glyn Wintle in WordPress Redirection plugin (versions <= 2.7.3).","date":"2018-06-20"}],"impact":[]},{"uuid":"fed8e858bf294924eb9f9e2d41b2b085cc9a68de597c48d28ae82f4af467e81e","name":"Redirection [redirection] < 2.3.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.3.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"bd4be0d884b06624c96b2cd82ec785712c52b4de","name":"WordPress Redirection Plugin <= 2.3.3 - Reflected XSS","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/redirection\/vulnerability\/wordpress-redirection-plugin-2-3-3-reflected-xss","description":"This plugin is prone to a reflected cross site scripting in view\/admin\/item.php .\nUpgrade the plugin.","date":"2015-05-15"}],"impact":[]},{"uuid":"e4f87b5e23e212dff89e09c00f9f7356fe6a33d3dbc90a19f072d5cb3888741a","name":"Redirection [redirection] < 2.2.9","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.2.9","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"2989e8ddefcd2a09d2fab304a2ba57dd2536d474","name":"WordPress Redirection Plugin <= 2.2.8 - Cross Site Scripting","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/redirection\/vulnerability\/wordpress-redirection-plugin-2-2-8-cross-site-scripting","description":"This plugin is prone to a cross site scripting vulnerability in wp-admin\/tools.php id parameter.\nUpdate the plugin.","date":"2015-05-15"}],"impact":[]},{"uuid":"5af05bf9a2a3c67ae20f5247751010f36fb0cbb96efb1b7316c43389b1b6722b","name":"Redirection [redirection] < 3.6.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.6.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"76f4b63cf33560b80ec3f8020f9f67d9b5d2ccd7","name":"Redirection <= 3.6.3 - Cross-Site Request Forgery to Remote Code Execution","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/redirection\/redirection-363-cross-site-request-forgery-to-remote-code-execution","description":"The Redirection plugin suffers from a critical Cross-Site Request Forgery vulnerability that allows remote attackers to create a file on the target server and execute arbitrary code.  The attack requires an administrator visit a malicious website set up by the attacker, but does not require more interaction nor do they have to click on anything on the malicious website in order to trigger the exploit.","date":"2018-11-14"}],"impact":[]},{"uuid":"7c0d2ab475b0ec37b3883396f4559d43e4a3862d1d306a60fb7cd9189b85a13b","name":"Redirection [redirection] < 2.8","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.8","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2018-1000504","name":"CVE-2018-1000504","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2018-1000504","description":"[en] Redirection version 2.7.3 contains a ACE via file inclusion vulnerability in Pass-through mode that can result in allows admins to execute any PHP file in the filesystem. This attack appear to be exploitable via Attacker must be have access to an admin account on the target site. This vulnerability appears to have been fixed in 2.8.","date":"2018-06-26"},{"id":"3e4237f20b16bf796aac51faa0467d4fb202b556","name":"Redirection <= 2.7.3 - Local File Inclusion","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/redirection\/redirection-273-local-file-inclusion","description":"Redirection version 2.7.3 contains a ACE via file inclusion vulnerability in Pass-through mode that can result in allows admins to execute any PHP file in the filesystem. This attack appear to be exploitable via Attacker must be have access to an admin account on the target site. This vulnerability appears to have been fixed in 2.8.","date":"2018-07-12"}],"impact":{"cvss":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:H\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"h","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"7.2","severity":"h","exploitable":"1.2","impact":"5.9"},"cvss3":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:H\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"7.2","severity":"high","av":"network","ac":"low","pr":"high","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"1.2","impact":"5.9"},"cwe":[{"cwe":"CWE-601","name":"URL Redirection to Untrusted Site ('Open Redirect')","description":"The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect."}]}},{"uuid":"1e4a734315a422d6286ee59db661e29ba6d3da6617cbf0c5211e59d288aca794","name":"Redirection [redirection] < 3.6.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.6.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"4209cf3b-1778-4ac2-b778-3bd5526b681d","name":"Redirection &lt;= 3.6.2 - Cross-Site Request Forgery (CSRF)","link":"https:\/\/wpscan.com\/vulnerability\/4209cf3b-1778-4ac2-b778-3bd5526b681d","description":"The Redirection WordPress plugin was affected by a Cross-Site Request Forgery (CSRF) security vulnerability.","date":null}],"impact":[]},{"uuid":"0e896cba6b5dd57014ccfc59e94fe2ac1dd45eb9dcb2251437ba215a8215e575","name":"Redirection [redirection] < 2.8","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.8","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"05f8bb60-7b66-4691-9519-ff9aa5fbe95d","name":"Redirection &lt;= 2.7.3 - Authenticated Local File Inclusion","link":"https:\/\/wpscan.com\/vulnerability\/05f8bb60-7b66-4691-9519-ff9aa5fbe95d","description":"The Redirection WordPress plugin was affected by an Authenticated Local File Inclusion security vulnerability.","date":null}],"impact":[]},{"uuid":"2ccdc7979730f4fb44b19ea7a2b57983e8416371c7c78c26a12f690fd99aa9ce","name":"Redirection [redirection] < 2.3.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.3.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"9d3daf86-f758-47cc-8db4-9e73a0f5428f","name":"Redirection 2.3.3 - view\/admin\/item.php URL Handling Reflected XSS","link":"https:\/\/wpscan.com\/vulnerability\/9d3daf86-f758-47cc-8db4-9e73a0f5428f","description":"The Redirection WordPress plugin was affected by a view\/admin\/item.php URL Handling Reflected XSS security vulnerability.","date":null}],"impact":[]}]},"updated":"1776563733"}