What is CVE-2026-13703?
In the SEO Redirection Plugin for WordPress before version 9.19, a missing capability check in an authenticated AJAX action allows any logged-in user, such as a subscriber, to read the site's configured 301 redirect rules, including source and destination URLs. This leads to the exposure of sensitive redirection data. Updating the plugin to version 9.19 or later is recommended to fix the issue.
Azərbaycanca: WordPress üçün SEO Redirection Plugin-in 9.19-dan əvvəlki versiyalarında bir autentifikasiya olunmuş AJAX əməliyyatı üzərində capability check aparılmadığından, sayta daxil olmuş istənilən abunəçi kimi aşağı səviyyəli istifadəçi saytın konfiqurasiya edilmiş 301 yönləndirmə qaydalarını (mənbə və hədəf URL-lər daxil) oxuya bilər. Bu, həssas yönləndirmə məlumatlarının ifşasına səbəb olur. Problemi aradan qaldırmaq üçün plaqini 9.19 və ya daha yuxarı versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
What can low-level users access in the SEO Redirection Plugin for WordPress before version 9.19?
Any logged-in user, such as a subscriber, can read the site's configured 301 redirect rules, including source and destination URLs due to a missing capability check in the plugin.
How is this vulnerability in the SEO Redirection Plugin fixed?
Updating the plugin to version 9.19 or later is recommended to fix the issue.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.