CVE-2023-1331: Inisev Redirection
Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.
The Redirection WordPress plugin before 1.1.5 does not have CSRF checks in the uninstall action, which could allow attackers to make logged in admins delete all the redirections through a CSRF attack.
Affected products
- Inisev Redirection: before 1.1.5 (fixed in 1.1.5)
Published 2023-04-17. Last modified 2026-06-17.