← WordPress Vulnerabilities
WordPress security by component

SEO Redirection Plugin

SEO Redirection Plugin creates and manages URL redirects for WordPress pages and posts.

SEO Redirection Plugin (seo-redirection-plugin) is a WordPress plugin with 3 published CVE records in this archive. The latest tracked vulnerability was published Aug 06, 2026; the highest published CVSS base score is 6.1.

Plugin slug: seo-redirection-plugin

CVE-2026-13703: SEO Redirection AJAX action exposes redirect rules to Subscribers

SEO Redirection Plugin before 9.19 registers the authenticated customUpdateRec AJAX action without a capability or nonce check. Any logged-in user, including a Subscriber, can POST action=customUpdateRec and an attacker-chosen ID to /wp-admin/admin-ajax.php. WPSR_customUpdateRec_callback() queries that row from the WP_SEO_Redirection table and returns redirect_from, redirect_to, redirect type, source, folder and destination settings, and enabled state as JSON. This permits low-privilege enumeration of configured redirect rules; practical sensitivity depends on the site's URLs.

PublishedAug 06, 2026
Known safe version9.19
Published vulnerabilities for seo-redirection-plugin
Safe version
Aug 06, 2026 CVE-2026-13703
SEO Redirection AJAX action exposes redirect rules to Subscribers
SEO Redirection Plugin before 9.19 registers the authenticated customUpdateRec AJAX action without a capability or nonce check. Any logged-in user, including a Subscriber, can POST action=customUpdateRec and an attacker-chosen ID to /wp-admin/admin-ajax.php. WPSR_customUpdateRec_callback() queries that row from the WP_SEO_Redirection table and returns redirect_from, redirect_to, redirect type, source, folder and destination settings, and enabled state as JSON. This permits low-privilege enumeration of configured redirect rules; practical sensitivity depends on the site's URLs.
9.19
CVE5.4
NVDPending
May 17, 2021 CVE-2021-24327
SEO Redirection Plugin – 301 Redirect Manager: Cross-site scripting
SEO Redirection Plugin – 301 Redirect Manager is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVEPending
NVD4.8
May 17, 2021 CVE-2021-24325
tab parameter of the settings page of the 404 SEO Redirection: Cross-site scripting
tab parameter of the settings page of the 404 SEO Redirection is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVEPending
NVD6.1