#VU27419 Improper Privilege Management in Quick Page/Post Redirect Plugin
Published: April 29, 2020
Quick Page/Post Redirect Plugin
anadnet
Description
The vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability exists due to a lack of capability check and a weak security nonce. A remote authenticated attacker can interact with the plugin settings and create a redirect link that would forward all traffic to an external malicious website.
Redirections are performed via the 'Location' header".