Description
WordPress Plugin Redirection is prone to a local file inclusion vulnerability because it fails to sufficiently verify user-supplied input. Exploiting this issue may allow an attacker to obtain sensitive information that could aid in further attacks. WordPress Plugin Redirection version 2.7.3 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.8 or latest
References
https://advisories.dxw.com/advisories/ace-file-inclusion-redirection/
https://packetstormsecurity.com/files/148167/WordPress-Redirection-2.7.3-Remote-File-Inclusion.html
Related Vulnerabilities
Oracle Application Server Other Vulnerability (CVE-2002-0655)
WordPress Plugin Opening Hours Cross-Site Scripting (2.3.0)
MySQL Numeric Errors Vulnerability (CVE-2010-3835)
WordPress Plugin FunCaptcha-Anti-Spam CAPTCHA Multiple Cross-Site Scripting Vulnerabilities (0.4.3)
MyBB Permissions, Privileges, and Access Controls Vulnerability (CVE-2016-9403)