AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-13703

MEDIUM · CVSS 5.4 EPSS 0.14%

Source: NVD + CISA KEV + EPSS · Published 2026-08-06 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The SEO Redirection Plugin for WordPress versions prior to 9.19 is vulnerable due to a lack of capability checks in an authenticated AJAX action, enabling any logged-in user, including subscribers, to access sensitive site configuration details such as 301 redirect rules. This exposure could lead to information leakage and potential exploitation of redirect vulnerabilities. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate these risks.

CVE
CVE-2026-13703
Severity
MEDIUM
CVSS
5.4
EPSS
0.14%
WordPress

Original NVD Description

The SEO Redirection Plugin WordPress plugin before 9.19 does not perform a capability check in one of its authenticated AJAX actions, allowing any logged-in user such as a subscriber to read the site's configured 301 redirect rules, including their source and destination URLs.