VYPR
Unrated severityNVD Advisory· Published May 14, 2021· Updated Aug 3, 2024

Redirection for Contact Form 7 < 2.3.4 - Unprotected AJAX Actions

CVE-2021-24282

Description

Authenticated users, including subscribers, can abuse unprotected AJAX actions in Redirection for Contact Form 7 before 2.3.4 to reset settings or add form actions.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Authenticated users, including subscribers, can abuse unprotected AJAX actions in Redirection for Contact Form 7 before 2.3.4 to reset settings or add form actions.

Vulnerability

The Redirection for Contact Form 7 WordPress plugin versions before 2.3.4 exposes multiple AJAX actions without proper capability checks. Any authenticated user, including subscribers, can perform actions such as resetting plugin settings via wpcf7r_reset_settings or adding new actions to forms via wpcf7r_add_action and similar endpoints [1]. The affected versions are all releases prior to 2.3.4.

Exploitation

An attacker needs only a valid WordPress user account with any role, including the lowest-privilege subscriber role. The attacker can directly call the unprotected AJAX endpoints by sending crafted requests, for example to wpcf7r_reset_settings or wpcf7r_add_action. No special authentication or user interaction beyond having a session cookie is required.

Impact

Successful exploitation allows the attacker to reset the plugin's configuration, delete existing redirection rules, and add arbitrary redirection actions to Contact Form 7 forms. This could lead to unintended data leaks or redirect users to malicious external sites, compromising the integrity and availability of the plugin's functionality [1].

Mitigation

The vulnerability is fixed in version 2.3.4 of the plugin. Users should update to this or a later version immediately. No workaround is provided for older versions [1]. The vulnerability is not listed on CISA's Known Exploited Vulnerabilities (KEV) catalog.

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.