WordPress 404 to 301 Plugin <= 3.0.5 is vulnerable to Cross Site Scripting (XSS)
404 to 301 – Redirect, Log and Notify 404 Errors
Minimum safe version
3.1.2
Update to 3.1.2 or later to address 19 fixable vulnerabilities
CVE-2021-4338
404 to 301 <= 2.3.0 - Unauthenticated Stored Cross-Site Scripting
Freemius SDK <= 2.2.3 - Missing Authorization to Arbitrary Options Update
404 to 301 <= 3.0.7 - Missing Authorization to Redirect Creation
404 to 301 – Redirect, Log and Notify 404 Errors <= 3.1.1 - Reflected Cross-Site Scripting
404 to 301 <= 2.3.0 - Unauthenticated Stored Cross-Site Scripting (XSS)
404 to 301 < 3.0.8 - Broken Access Control
Freemius Library < 2.2.4 - Subscriber+ Arbitrary Option Update
404 to 301 < 3.1.2 - Reflected Cross-Site Scripting
WordPress 404 to 301 plugin <= 3.1.1 - Reflected Cross-Site Scripting (XSS) vulnerability
WordPress 404 to 301 Plugin <= 2.0.2 - Blind SQL Injection
WordPress 404 to 301 Plugin <= 2.3.0 - Cross Site Scripting
WordPress 404 to 301 Plugin <= 2.3.1 - Persistent Cross-Site Scripting (XSS) Vulnerability
WordPress 404 to 301 Plugin <= 2.2.8 - Persistent Cross Site Scripting
WordPress 404 to 301 plugin <= 3.0.1 - Authenticated Option Update vulnerability (Fremius Library security issue)
WordPress 404 to 301 plugin <= 3.0.7 - Broken Access Control vulnerability
CVE-2015-9323
CVE-2021-24766