Description
Missing Authorization vulnerability in solwininfotech Trash Duplicate and 301 Redirect trash-duplicate-and-301-redirect allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Trash Duplicate and 301 Redirect: from n/a through <= 1.9.1.
Published: 2025-12-31
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is a missing authorization flaw that permits attackers to gain elevated privileges within the Trash Duplicate and 301 Redirect plugin. Because the plugin’s access controls are incorrectly configured, an attacker who reaches a managed site can modify plugin settings or exploit other misconfigurations, potentially leading to unauthorized changes or further compromise. The weakness is classified as CWE-862, indicating a flaw in access control. The impact is therefore an escalation of privileges that could affect the confidentiality, integrity, or availability of the web application.

Affected Systems

The affected product is the WordPress plugin Trash Duplicate and 301 Redirect developed by solwininfotech. All releases from the initial version up through version 1.9.1 are vulnerable. The vulnerability description does not list specific patch versions beyond that threshold.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate severity, while an EPSS score of less than 1% shows a low probability of exploitation discovered in the public dataset. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is web-based through a WordPress site that has the vulnerable plugin active; an attacker would need to interact with the plugin’s interfaces to take advantage of the access-control flaw. Because the flaw allows unauthorized configuration changes, it can serve as a stepping stone for broader attacks on the site if combined with other vulnerabilities.

Generated by OpenCVE AI on April 29, 2026 at 17:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Trash Duplicate and 301 Redirect to the latest stable release newer than 1.9.1
  • If upgrading is not feasible, uninstall or disable the plugin entirely to eliminate the exposed access control
  • Configure role-based access controls so that only trusted administrators can manage plugin settings
  • Regularly review WordPress user roles and limit the number of accounts with high privileges

Generated by OpenCVE AI on April 29, 2026 at 17:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Solwininfotech Trash Duplicate and 301 Redirect allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Trash Duplicate and 301 Redirect: from n/a through 1.9.1. Missing Authorization vulnerability in solwininfotech Trash Duplicate and 301 Redirect trash-duplicate-and-301-redirect allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Trash Duplicate and 301 Redirect: from n/a through <= 1.9.1.
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}


Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Mon, 05 Jan 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Wed, 31 Dec 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 31 Dec 2025 15:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Solwininfotech Trash Duplicate and 301 Redirect allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Trash Duplicate and 301 Redirect: from n/a through 1.9.1.
Title WordPress Trash Duplicate and 301 Redirect plugin <= 1.9.1 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:14:02.247Z

Reserved: 2025-10-07T15:41:34.897Z

Link: CVE-2025-62122

cve-icon Vulnrichment

Updated: 2025-12-31T16:51:07.955Z

cve-icon NVD

Status : Deferred

Published: 2025-12-31T16:15:45.010

Modified: 2026-04-23T15:34:34.977

Link: CVE-2025-62122

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T18:00:13Z

Weaknesses