Redirection <= 3.6.3 - Cross-Site Request Forgery to Remote Code Execution

Cross-Site Request Forgery (CSRF)
CVE Not available
CVSS High (8.8)
Publicly Published November 14, 2018
Last Updated January 22, 2024
Researcher RIPS Technologies
Description

The Redirection plugin suffers from a critical Cross-Site Request Forgery vulnerability that allows remote attackers to create a file on the target server and execute arbitrary code. The attack requires an administrator visit a malicious website set up by the attacker, but does not require more interaction nor do they have to click on anything on the malicious website in order to trigger the exploit.

References

1 affected software package

Software Type Plugin
Software Slug redirection (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 3.6.3
Patched Version
  • 3.6.4
This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.
License: Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy. License Detail.