The Redirection WordPress plugin before 1.1.5 does not have CSRF checks in the uninstall action, which could allow attackers to make logged in admins delete all the redirections through a CSRF attack.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Redirection | Inisev | * | 1.1.5 (excluding) |