CVE-2023-1330
The Redirection WordPress plugin before 1.1.4 does not add nonce verification in place when adding the redirect, which could allow attackers to add redirects via a CSRF attack.
- Affected products
- Redirection
- Inisev Redirection
- < 1.1.4
- Fix
- Available
- CVSS 3.1
- 6.5 MEDIUM
- EPSS
- 0.3% (27th percentile)
- Weakness
- CWE-352
- NVD status
- Modified
- Published
- 2023-04-03
CVE-2023-1330 at NVD
1 known exploit for CVE-2023-1330
Proof-of-concept code and exploit modules indexed by Sploitus