CVE detail
CVE-2021-24355 — CVE-2021-24355
Published 2021-06-14 · Modified 2026-06-17 · Vendor wpdeveloper · Product simple_301_redirects · Source nvd
MEDIUM
severity
CVSS-derived band
0.0072
EPSS probability
exploitation probability, 30d
50.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
In the Simple 301 Redirects by BetterLinks WordPress plugin before 2.0.4, the lack of capability checks and insufficient nonce check on the AJAX actions, simple301redirects/admin/get_wildcard and simple301redirects/admin/wildcard, made it possible for authenticated users to retrieve and update the wildcard value for redirects.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References