The Redirection WordPress plugin before 1.1.5 does not have CSRF checks in the uninstall action, which could allow attackers to make logged in admins delete all the redirections through a CSRF attack.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Redirection | Inisev | * | 1.1.5 (excluding) |