vulnerability

WordPress Plugin: quick-pagepost-redirect-plugin: CVE-2020-36699: Improper Access Control

Severity
4
CVSS
(AV:N/AC:L/Au:S/C:N/I:P/A:N)
Published
Apr 28, 2020
Added
May 15, 2025
Modified
Jun 24, 2025

Description

The Quick Page/Post Redirect Plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on the qppr_save_quick_redirect_ajax and qppr_delete_quick_redirect functions in versions up to, and including, 5.1.9. This makes it possible for low-privileged attackers to interact with the plugin settings and to create a redirect link that would forward all traffic to an external malicious website.

Solution

quick-pagepost-redirect-plugin-plugin-cve-2020-36699
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.