Impact
The SEO Redirection Plugin fails to verify user capabilities for a specific authenticated AJAX action. The lack of a capability check results in improper access control (CWE‑284), leading to the disclosure of redirect rules. This oversight allows any authenticated user to read the configured 301 redirect entries, which include source and destination URLs. Based on the description, it is inferred that an attacker could use this information to understand site structure or craft phishing or other targeted attacks.
Affected Systems
WordPress sites that have the SEO Redirection Plugin installed in versions earlier than 9.19. Any user logged into the site with at least subscriber‑level access can exploit the flaw.
Risk and Exploitability
The vulnerability requires only a standard authenticated session; elevated privileges are not needed. The EPSS score is below 1%, and the flaw is not listed in CISA KEV. The ease of exploitation combined with the strategic value of the redirect rules means the risk to affected installations is significant. Based on the description, it is inferred that an attacker can simply issue the vulnerable AJAX request under a valid user session to retrieve the redirect table.
OpenCVE Enrichment