Description
WordPress Plugin 404 to 301-Redirect, Log and Notify 404 Errors is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently view, create, or edit redirections. WordPress Plugin 404 to 301-Redirect, Log and Notify 404 Errors version 3.0.7 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 3.0.8 or latest
References
Related Vulnerabilities
WordPress Plugin Downloads Manager 'upload.php' Arbitrary File Upload (0.2)
Joomla! Core 2.5.x Cross-Site Scripting (2.5.0 - 2.5.6)
PHP Use of Externally-Controlled Format String Vulnerability (CVE-2010-2094)
Drupal Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2020-13675)
WordPress Plugin Favicon by RealFaviconGenerator Cross-Site Scripting (1.2.12)