The 404 Redirection Manager plugin version 1.0 for WordPress contains an unauthenticated SQL injection vulnerability that allows remote attackers to execute arbitrary SQL queries by injecting malicious code through unsanitized user input. Attackers can craft GET requests with SQL injection payloads to manipulate database queries and extract sensitive information from the WordPress database.
Metrics
Affected Vendors & Products
References
History
Mon, 15 Jun 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 15 Jun 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The 404 Redirection Manager plugin version 1.0 for WordPress contains an unauthenticated SQL injection vulnerability that allows remote attackers to execute arbitrary SQL queries by injecting malicious code through unsanitized user input. Attackers can craft GET requests with SQL injection payloads to manipulate database queries and extract sensitive information from the WordPress database. | |
| Title | WordPress 404 Redirection Manager Plugin 1.0 SQL Injection | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-06-15T14:51:51.754Z
Reserved: 2026-06-15T11:37:01.880Z
Link: CVE-2016-20071
Updated: 2026-06-15T14:51:48.495Z
Status : Received
Published: 2026-06-15T14:16:30.223
Modified: 2026-06-15T14:16:30.223
Link: CVE-2016-20071
No data.
OpenCVE Enrichment
No data.