The Redirect Redirection plugin for WordPress is vulnerable to changes that shouldn’t be allowed. This vulnerability affects versions up to and including 1.1.3. If someone with an account on the site has at least a subscriber-level access, they could delete redirects, which is not allowed.