Input validation vulnerability in 404 to 301 – Redirect, Log and Notify 404 Errors 2.3.0

The 404 to 301 plugin for WordPress had a security vulnerability in versions before 2.3.1. This vulnerability caused pages to be open to attack from unauthenticated attackers. These attackers could inject web scripts into pages, which would execute any time a user viewed the page. This was due to the plugin not properly filtering or protecting the ‘Referer’ and ‘User-Agent’ HTTP Headers.

Detected in:

404 to 301 – Redirect, Log and Notify 404 Errors fixed vulnerable versions: >= * <= 2.3.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.