The Redirect Redirection plugin for WordPress has a security vulnerability that allows people with subscriber-level access or higher to access data they shouldn’t be allowed to see. This vulnerability exists in versions up to and including 1.1.3 and is caused by the logFilter function not checking if the user has the proper permission.