Description
WordPress Plugin Redirection is prone to a local file inclusion vulnerability because it fails to sufficiently verify user-supplied input. Exploiting this issue may allow an attacker to obtain sensitive information that could aid in further attacks. WordPress Plugin Redirection version 2.7.3 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.8 or latest
References
https://advisories.dxw.com/advisories/ace-file-inclusion-redirection/
https://packetstormsecurity.com/files/148167/WordPress-Redirection-2.7.3-Remote-File-Inclusion.html
Related Vulnerabilities
Jetty Uncontrolled Resource Consumption Vulnerability (CVE-2020-27223)
ProjectSend Authorization Bypass Through User-Controlled Key Vulnerability (CVE-2017-20101)
Apache HTTP Server CVE-2024-38476 Vulnerability (CVE-2024-38476)
WordPress Plugin AppPresser-Mobile App Framework Security Bypass (4.3.2)
WordPress Plugin Elementor Website Builder Security Bypass (3.0.13)