WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in Redirection

Manage 301 redirects, track 404 errors, and improve your site. No knowledge of Apache or Nginx required.

8Reported vulnerabilities
8.8Highest CVSS score
5.9.0Latest version
2,000,000+Active installs

What to do now

Update Redirection to 1.1.5 or later. 7 of these have a fixed version available. Updating resolves them.

Plugin last updated: July 11, 2026 / Tested up to WordPress: 7.0.4 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2015-1580 Medium 6.8 1.0% 1.2 to 1.2 (inclusive) February 11, 2015
CVE-2023-1331 Medium 6.5 0.3% Before 1.1.5 1.1.5 April 17, 2023
CVE-2023-1330 Medium 6.5 0.3% Before 1.1.4 1.1.4 April 3, 2023
WF-f2862cee-0412-42ba-9a8e-e5722bece775 High 8.8 3.6.3 and earlier 3.6.4 November 14, 2018
CVE-2018-1000504 High 7.2 2.0% 2.7.3 and earlier 2.8 July 12, 2018
CVE-2012-6717 Medium 6.1 0.9% Before 2.2.12 2.2.12 August 28, 2019
CVE-2011-5329 Medium 6.1 0.9% Before 2.2.9 2.2.9 August 28, 2019
CVE-2011-4562 Medium 5.3 2.4% Before 2.2.10 2.2.10 August 1, 2014

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.