Executive brief
The Advanced 301 and 302 Redirect plugin for WordPress, which manages website link forwarding, contains a critical security flaw. An unauthorized attacker can use this vulnerability to access and steal sensitive information from the website's database. This could lead to the exposure of user data or administrative credentials, potentially compromising the entire site.
Technical details
A SQL injection vulnerability exists in the Advanced 301 and 302 Redirect plugin for WordPress (versions <= 1.6.9) due to improper neutralization of special elements used in SQL commands (CWE-89). The flaw is exploitable by unauthenticated remote attackers over the network with low complexity. By sending specially crafted requests, an attacker can bypass security controls to execute arbitrary SQL queries against the backend database. This can result in unauthorized data exfiltration or limited impact on service availability. The issue is resolved in version 1.7.0.
Affected products
- WordPress Plugin Advanced 301 and 302 Redirect <= 1.6.9
Timeline
- 2026-06-01: other: Reported by researcher dodoh4t
- 2026-06-08: advisory: Patchstack advisory published
- 2026-06-15: disclosed: CVE published to NVD