Input validation vulnerability in Redirection 1.1.3

The Redirect Redirection plugin for WordPress is not secure in versions of 1.1.3 or lower. This means that it is possible for unauthenticated attackers to change redirects, without needing to be logged in, as long as they can convince a site administrator to do something, such as clicking on a link. This is a result of the missing or incorrect validation of a nonce on the instantEditRedirect function.

Detected in:

Redirection fixed vulnerable versions:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.