CVE-2021-24354: fallo en Simple 301 Redirects by BetterLinks
Simple 301 Redirects by BetterLinks - 2.0.0-2.0.3 - Arbitrary Plugin Installation
Publicada el · Actualizada el
3Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackepss 1.5%
probabilidad de explotación
1.5%top 27% de las CVE
explotación observada
noninguna fuente lo reporta
A lack of capability checks and insufficient nonce check on the AJAX action in the Simple 301 Redirects by BetterLinks WordPress plugin before 2.0.4, made it possible for authenticated users to install arbitrary plugins on vulnerable sites.
Productos afectados
Unknown · Simple 301 Redirects by BetterLinksCVEs relacionadas — Simple 301 Redirects by BetterLinks
En el mismo producto, de las más peligrosas a las menos.
CVE-2021-24356—Simple 301 Redirects by BetterLinks - 2.0.0 – 2.0.3 - Arbitrary Plugin ActivationEPSS 2.6%CVE-2021-24352—Simple 301 Redirects by BetterLinks - 2.0.0 – 2.0.3 - Unauthenticated Redirect ExportEPSS 1.2%CVE-2021-24353—Simple 301 Redirects by BetterLinks - 2.0.0 – 2.0.3 - Unauthenticated Redirect ImportEPSS 1.1%CVE-2021-24355—Simple 301 Redirects by BetterLinks - 2.0.0 – 2.0.3 - Update and Retrieve Wildcard ValueEPSS 0.7%