WP-Redirection WordPress Plugin Cross-Site Request Forgery Vulnerability

Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WP-Redirection plugin for WordPress, affecting all versions up to and including 1.0.3. The vulnerability arises from the lack of a nonce field in the admin settings form and the absence of nonce verification in the 'displayWPRedirectionManagementPage()' function. This oversight allows unauthenticated attackers to manipulate logged-in administrators into clicking malicious links, which can result in unauthorized creation, modification, or deletion of URL redirection rules in the plugin's database.

Impact

Exploitation of this vulnerability allows for unauthorized changes to be made to the redirection rules, potentially leading to malicious redirects.

Reproduction

To reproduce this vulnerability, an attacker can send a crafted link to a logged-in administrator. This link, when clicked, will trigger the 'displayWPRedirectionManagementPage()' function without proper nonce verification, allowing the attacker to manipulate redirection rules in the database.

Added: May 12, 2026, 9:25 AM
Updated: May 12, 2026, 9:25 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
7.2
remediation
0.0
relevance
8.1
threat
4.8
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.