PatchSiren

404-redirection-manager CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH 404-redirection-manager CVE published 2026-06-15

CVE-2016-20071

CVE-2016-20071 is an unauthenticated SQL injection vulnerability in the 404 Redirection Manager plugin version 1.0 for WordPress. The vulnerability allows remote attackers to execute arbitrary SQL queries by injecting malicious code through unsanitized user input. Attackers can craft GET requests with SQL injection payloads to manipulate database queries and extract sensitive information from the WordPress database.