The Redirect Redirection plugin for WordPress is vulnerable to a security risk up to version 1.1.3. Attackers who can trick a site administrator into clicking on a link, can use a forged request to bulk edit the redirect rules without needing to be authenticated. This is due to the statusBulkEdit function not having the correct security validation.