The Redirect Redirection plugin for WordPress is vulnerable to changes it wasn’t supposed to have. This vulnerability affects versions up to, and including, 1.1.3 of the plugin. This means that anyone with a subscriber level account (or higher) on the vulnerable website could add redirects to the site without the proper authorization.