CVE-2026-4202: Ayacoo Redirect Tab

Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.

The extension fails to verify, if an authenticated user has permissions to access to redirects resulting in exposure of redirect records when editing a page.

Affected products

  • Ayacoo Redirect Tab: before 2.1.2 (fixed in 2.1.2); from 3.0.0, before 3.1.7 (fixed in 3.1.7); from 4.0.0, before 4.0.5 (fixed in 4.0.5)

Published 2026-03-17. Last modified 2026-06-17.