The Redirection plugin has a security issue that could allow malicious attackers to create files and execute code on a targeted server. All that is needed for this attack to work is for an administrator of the server to visit a website set up by the attacker. No extra interaction or clicks are necessary.