CVE-2021-24355: vulnerability in Simple 301 Redirects by BetterLinks
Simple 301 Redirects by BetterLinks - 2.0.0 – 2.0.3 - Update and Retrieve Wildcard Value
Published · Updated
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 0.7%
exploitation probability
0.7%top 48% of all CVEs
observed exploitation
nono source reports it
In the Simple 301 Redirects by BetterLinks WordPress plugin before 2.0.4, the lack of capability checks and insufficient nonce check on the AJAX actions, simple301redirects/admin/get_wildcard and simple301redirects/admin/wildcard, made it possible for authenticated users to retrieve and update the wildcard value for redirects.
Affected products
Unknown · Simple 301 Redirects by BetterLinksRelated CVEs — Simple 301 Redirects by BetterLinks
In the same product, most dangerous first.
CVE-2021-24356—Simple 301 Redirects by BetterLinks - 2.0.0 – 2.0.3 - Arbitrary Plugin ActivationEPSS 2.6%CVE-2021-24354—Simple 301 Redirects by BetterLinks - 2.0.0-2.0.3 - Arbitrary Plugin InstallationEPSS 1.5%CVE-2021-24352—Simple 301 Redirects by BetterLinks - 2.0.0 – 2.0.3 - Unauthenticated Redirect ExportEPSS 1.2%CVE-2021-24353—Simple 301 Redirects by BetterLinks - 2.0.0 – 2.0.3 - Unauthenticated Redirect ImportEPSS 1.1%