CVE-2021-24354: vulnerability in Simple 301 Redirects by BetterLinks
Simple 301 Redirects by BetterLinks - 2.0.0-2.0.3 - Arbitrary Plugin Installation
Published · Updated
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 1.5%
exploitation probability
1.5%top 27% of all CVEs
observed exploitation
nono source reports it
A lack of capability checks and insufficient nonce check on the AJAX action in the Simple 301 Redirects by BetterLinks WordPress plugin before 2.0.4, made it possible for authenticated users to install arbitrary plugins on vulnerable sites.
Affected products
Unknown · Simple 301 Redirects by BetterLinksRelated CVEs — Simple 301 Redirects by BetterLinks
In the same product, most dangerous first.
CVE-2021-24356—Simple 301 Redirects by BetterLinks - 2.0.0 – 2.0.3 - Arbitrary Plugin ActivationEPSS 2.6%CVE-2021-24352—Simple 301 Redirects by BetterLinks - 2.0.0 – 2.0.3 - Unauthenticated Redirect ExportEPSS 1.2%CVE-2021-24353—Simple 301 Redirects by BetterLinks - 2.0.0 – 2.0.3 - Unauthenticated Redirect ImportEPSS 1.1%CVE-2021-24355—Simple 301 Redirects by BetterLinks - 2.0.0 – 2.0.3 - Update and Retrieve Wildcard ValueEPSS 0.7%