vulnerability
WordPress Plugin: quick-pagepost-redirect-plugin: CVE-2020-36699: Improper Access Control
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 4 | (AV:N/AC:L/Au:S/C:N/I:P/A:N) | Apr 28, 2020 | May 15, 2025 | Jun 24, 2025 |
Severity
4
CVSS
(AV:N/AC:L/Au:S/C:N/I:P/A:N)
Published
Apr 28, 2020
Added
May 15, 2025
Modified
Jun 24, 2025
Description
The Quick Page/Post Redirect Plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on the qppr_save_quick_redirect_ajax and qppr_delete_quick_redirect functions in versions up to, and including, 5.1.9. This makes it possible for low-privileged attackers to interact with the plugin settings and to create a redirect link that would forward all traffic to an external malicious website.
Solution
quick-pagepost-redirect-plugin-plugin-cve-2020-36699
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.