The Redirect Redirection plugin for WordPress is not secure in versions of 1.1.3 or lower. This means that it is possible for unauthenticated attackers to change redirects, without needing to be logged in, as long as they can convince a site administrator to do something, such as clicking on a link. This is a result of the missing or incorrect validation of a nonce on the instantEditRedirect function.