Impact
The vulnerability is a Cross‑Site Request Forgery flaw that permits an attacker to force a logged‑in user to trigger unintended actions within the Easy 301 Redirects plugin. Because the plugin handles redirect rules, the attacker could potentially create, modify, or delete redirect entries, altering site behavior or redirecting users to malicious destinations. The weakness is categorized as CWE‑352.
Affected Systems
The plugin affected is odihost Easy 301 Redirects, version 1.33 and earlier.
Risk and Exploitability
The CVSS score is 4.3, indicating a moderate risk level. The EPSS score of less than 1% shows a very low probability of exploitation at the time of analysis, and the vulnerability is not listed in CISA's KEV catalog. The likely attack vector is a web‑based CSRF attack that requires the victim to be authenticated to the WordPress site; the attacker only needs to trick the user into visiting a crafted link or form submission.
OpenCVE Enrichment
EUVD