WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in 404 to 301 – Redirect Manager, 404 Error Logs & Notifications

Custom redirects (301, 302, 307), automatic 404 redirection, full 404 error logs and email alerts — a complete redirect & 404 toolkit.

5Reported vulnerabilities
9.8Highest CVSS score
4.0.2Latest version
100,000+Active installs

What to do now

Update 404 to 301 – Redirect Manager, 404 Error Logs & Notifications to 3.0.8 or later. 5 of these have a fixed version available. Updating resolves them.

Plugin last updated: June 22, 2026 / Tested up to WordPress: 7.0.4 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2015-9323 Critical 9.8 46.1% Before 2.0.3 2.0.3 August 16, 2019
CVE-2021-24766 Medium 6.5 0.5% Before 3.0.9 3.0.9 November 8, 2021
CVE-2021-4338 Medium 5.4 0.6% 3.0.7 and earlier 3.0.8 June 7, 2023
WF-28624634-9161-4da7-89f3-88ce1d38c3ea High 7.2 2.3.0 and earlier 2.3.1 August 27, 2016
WF-11177270-cc73-4c65-9f72-8c0a0a89bed5 Medium 6.1 3.1.1 and earlier 3.1.2 June 7, 2022

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.