CVSS
5.4
CVSS v3.1
EPSS
0.1%
Exploit Prediction Score
Published
August 6, 2026
Exploitability
EPSS probability 0.1%
The SEO Redirection Plugin WordPress plugin before 9.19 does not perform a capability check in one of its authenticated AJAX actions, allowing any logged-in user such as a subscriber to read the site's configured 301 redirect rules, including their source and destination URLs.
No package data available.
Publisher and database URLs for this record (shown for attribution; reading stays in Bugflare).