The Redirect Redirection plugin for WordPress, up to version 1.1.3, has a security vulnerability related to Cross-Site Request Forgery. This means that if a malicious actor can get a site administrator to click on a link, they can add redirect rules without needing to authenticate. The issue is due to the addRedirectRule function not having the necessary protections in place.