The 404 Redirection Manager plugin version 1
Description
The 404 Redirection Manager plugin version 1
AI Analyst Comment
Remediation
Update WordPress plugin/theme to the latest version. Review WordPress security settings and remove if no longer needed.
---METADATA---
VENDOR: WordPress
PRODUCT: 404 Redirection Manager
AFFECTED_VERSIONS: See vendor advisory for specific affected versions
---END_METADATA---
Description Summary:
The WordPress 404 Redirection Manager plugin contains a security vulnerability that may expose the application to unauthorized actions.
Executive Summary:
A high-severity vulnerability in the 404 Redirection Manager plugin exposes the host WordPress environment to potential security compromises.
Vulnerability Details
CVE-ID: CVE-2016-20071
Affected Software: WordPress 404 Redirection Manager
Affected Versions: See vendor advisory for specific affected versions
Vulnerability: This vulnerability involves a flaw in the 404 Redirection Manager plugin, which may permit unauthorized access or manipulation of site redirection settings.
Business Impact
The CVSS score of 8.2 indicates a high risk to the business, as an attacker could potentially redirect traffic to malicious sites or manipulate site navigation, leading to a loss of user trust. Unauthorized control over redirection settings can also be leveraged to facilitate phishing campaigns against site visitors.
Remediation Plan
Immediate Action: Update the 404 Redirection Manager plugin to the latest version recommended by the vendor.
Proactive Monitoring: Regularly audit redirection rules and monitor logs for unexpected changes to site configuration files.
Compensating Controls: Implement a WAF to monitor and block suspicious HTTP requests that deviate from normal site navigation patterns.
Exploitation Status
Public Exploit Available: false
Analyst Notes: As of June 16, 2026, there is no public information indicating active exploitation of this vulnerability. Nevertheless, the high-severity classification requires prompt remediation.
Analyst Recommendation
Security teams should prioritize updating the 404 Redirection Manager plugin to mitigate this high-risk vulnerability. If the plugin is not actively required for business operations, it should be removed to reduce the overall attack surface.