PatchSiren cyber security CVE debrief
CVE-2026-13703 WordPress.org CVE debrief
The SEO Redirection Plugin for WordPress, version before 9.19, contains a vulnerability allowing logged-in users, including subscribers, to read the site's configured 301 redirect rules. This is due to a lack of capability checks in an authenticated AJAX action. The vulnerability has a CVSS score of 5.4 and is considered medium severity. WordPress administrators and users with the SEO Redirection Plugin installed should review their installations and consider updating to version 9.19 or later. The CVE record was published on 2026-08-06T07:16:27.320Z and has not been modified since then.
- Vendor
- WordPress.org
- Product
- SEO Redirection Plugin
- CVSS
- MEDIUM 5.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-06
- Original CVE updated
- 2026-08-06
- Advisory published
- 2026-08-06
- Advisory updated
- 2026-08-06
Who should care
WordPress administrators and users with SEO Redirection Plugin installed, especially those allowing public user registration, should review their installations and consider updating to version 9.19 or later. Additionally, security teams and vulnerability management teams should be aware of this vulnerability and its potential impact on their organizations.
Technical summary
The SEO Redirection Plugin for WordPress before version 9.19 does not perform capability checks in an authenticated AJAX action, allowing logged-in users like subscribers to access the site's 301 redirect rules, including source and destination URLs. This vulnerability can lead to unauthorized information disclosure. The plugin's lack of proper access controls enables attackers to read sensitive configuration data.
Defensive priority
Medium-priority defensive review recommended due to potential for unauthorized information disclosure via 301 redirect rules.
Recommended defensive actions
- Review and inventory WordPress installations with SEO Redirection Plugin versions before 9.19
- Restrict access to sensitive configuration data
- Monitor for suspicious access to 301 redirect rules
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
Evidence notes
Evidence from the NVD and WPScan suggests that the SEO Redirection Plugin for WordPress has a vulnerability allowing logged-in users to read 301 redirect rules. Further review is needed to assess the affected scope and vendor remediation. The vulnerability allows unauthorized information disclosure via 301 redirect rules. Affected users should verify their installations and consider updating to mitigate the vulnerability.
Official resources
-
CVE-2026-13703 CVE record
CVE.org
-
CVE-2026-13703 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T07:16:27.320Z and has not been modified since then.