Description
The SEO Redirection Plugin WordPress plugin before 9.19 does not perform a capability check in one of its authenticated AJAX actions, allowing any logged-in user such as a subscriber to read the site's configured 301 redirect rules, including their source and destination URLs.
Published: 2026-08-06
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The SEO Redirection Plugin fails to verify user capabilities for a specific authenticated AJAX action. The lack of a capability check results in improper access control (CWE‑284), leading to the disclosure of redirect rules. This oversight allows any authenticated user to read the configured 301 redirect entries, which include source and destination URLs. Based on the description, it is inferred that an attacker could use this information to understand site structure or craft phishing or other targeted attacks.

Affected Systems

WordPress sites that have the SEO Redirection Plugin installed in versions earlier than 9.19. Any user logged into the site with at least subscriber‑level access can exploit the flaw.

Risk and Exploitability

The vulnerability requires only a standard authenticated session; elevated privileges are not needed. The EPSS score is below 1%, and the flaw is not listed in CISA KEV. The ease of exploitation combined with the strategic value of the redirect rules means the risk to affected installations is significant. Based on the description, it is inferred that an attacker can simply issue the vulnerable AJAX request under a valid user session to retrieve the redirect table.

Generated by OpenCVE AI on August 6, 2026 at 19:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the SEO Redirection Plugin to version 9.19 or later, where the capability check has been added.
  • If an upgrade is not immediately possible, disable or block the AJAX endpoint that exposes redirect rules, for example by applying a web‑application firewall rule or modifying the plugin’s code to reject unauthorised access.
  • Restrict the ability to view or manage redirect rules to administrator‑level accounts only, ensuring that subscribers cannot trigger the vulnerable action even if the endpoint remains accessible.

Generated by OpenCVE AI on August 6, 2026 at 19:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 07 Aug 2026 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Clogica
Clogica seo Redirection Plugin
Wordpress
Wordpress wordpress
Vendors & Products Clogica
Clogica seo Redirection Plugin
Wordpress
Wordpress wordpress

Thu, 06 Aug 2026 18:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200

Thu, 06 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 06 Aug 2026 08:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-284

Thu, 06 Aug 2026 06:30:00 +0000

Type Values Removed Values Added
Description The SEO Redirection Plugin WordPress plugin before 9.19 does not perform a capability check in one of its authenticated AJAX actions, allowing any logged-in user such as a subscriber to read the site's configured 301 redirect rules, including their source and destination URLs.
Title SEO Redirection Plugin – 301 Redirect Manager < 9.19 - Subscriber+ Redirect Rule Disclosure
References

Subscriptions

Clogica Seo Redirection Plugin
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-06T15:32:48.460Z

Reserved: 2026-06-29T13:13:39.399Z

Link: CVE-2026-13703

cve-icon Vulnrichment

Updated: 2026-08-06T15:32:37.530Z

cve-icon NVD

Status : Deferred

Published: 2026-08-06T07:16:27.320

Modified: 2026-08-26T16:31:16.753

Link: CVE-2026-13703

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T09:15:07Z

Weaknesses