The CreateRedirect extension before 2022-04-14 for MediaWiki does not properly check whether the user has permissions to edit the target page. This could lead to an unauthorised (or blocked) user being able to edit a page.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.009
EPSS Ranking 56.1%