Junglewise Threat Intelligence

CVE-2025-62122: solwininfotech Trash Duplicate and 301 Redirect broken access control

CVE-2025-62122 · Severity: medium · CVSS 5.3 · Published 2025-12-31

Executive brief

The Trash Duplicate and 301 Redirect WordPress plugin contains a broken access control vulnerability that allows unauthenticated users to access restricted pages or perform actions they should not be permitted to perform. This could enable attackers to view sensitive data or modify site functionality without proper authorization, potentially compromising the confidentiality and integrity of the affected WordPress site.

Technical details

This is a broken access control vulnerability (CWE-639) affecting the Trash Duplicate and 301 Redirect WordPress plugin versions up to and including 1.9.1. The plugin fails to properly validate user permissions before allowing access to sensitive functions or data, allowing unauthenticated attackers to bypass intended access restrictions. The vulnerability is exploitable remotely without authentication required. An attacker can access protected pages, retrieve sensitive information, or perform restricted administrative actions. No official patch has been released as of the disclosure date.

Affected products

  • solwininfotech Trash Duplicate and 301 Redirect <= 1.9.1

Timeline

  • 2025-10-13: disclosed: Vulnerability reported
  • 2025-12-31: advisory: Published by Patchstack

References