AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2020-36699

MEDIUM · CVSS 4.3 EPSS 0.78%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2023-06-07 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2020-36699
Severity
MEDIUM
CVSS
4.3
EPSS
0.78%
WordPress

Original NVD Description

The Quick Page/Post Redirect Plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on the qppr_save_quick_redirect_ajax and qppr_delete_quick_redirect functions in versions up to, and including, 5.1.9. This makes it possible for low-privileged attackers to interact with the plugin settings and to create a redirect link that would forward all traffic to an external malicious website.