← WordPress Vulnerabilities
WordPress security by component

404 To 301

404 To 301 redirects 404 error pages to configured destinations using 301 redirects.

404 To 301 (404-to-301) is a WordPress plugin with 3 published CVE records in this archive. The latest tracked vulnerability was published Jun 07, 2023; the highest published CVSS base score is 9.8.

Plugin slug: 404-to-301

CVE-2021-4338: 404 to 301: A security weakness

404 to 301 is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation.

PublishedJun 07, 2023
Safe version guidanceSee mitigation notes
Published vulnerabilities for 404-to-301
Safe version
Jun 07, 2023 CVE-2021-4338
404 to 301: A security weakness
404 to 301 is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.4
NVD5.4
Nov 08, 2021 CVE-2021-24766
404 to 301 – Redirect, Log and Notify 404 Errors: Cross-site request forgery
404 to 301 – Redirect, Log and Notify 404 Errors is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVEPending
NVD6.5
Aug 16, 2019 CVE-2015-9323
404 To 301: SQL injection
404 To 301 is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVEPending
NVD9.8