VYPR

Redirection for Contact Form 7

by WordPress

Source repositories

CVEs (16)

  • CVE-2025-8145HigAug 20, 2025
    risk 0.57cvss 8.8epss 0.01

    The Redirection for Contact Form 7 plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.2.4 via deserialization of untrusted input in the get_lead_fields function. This makes it possible for unauthenticated attackers to inject a PHP…

  • CVE-2025-8141HigAug 20, 2025
    risk 0.57cvss 8.8epss 0.01

    The Redirection for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_associated_files function in all versions up to, and including, 3.2.4. This makes it possible for unauthenticated attackers to…

  • CVE-2021-24280HigMay 14, 2021
    risk 0.57cvss 8.8epss 0.02

    In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, any authenticated user, such as a subscriber, could use the import_from_debug AJAX action to inject PHP objects.

  • CVE-2025-8289HigAug 20, 2025
    risk 0.49cvss 7.5epss 0.00

    The Redirection for Contact Form 7 plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.2.4 via deserialization of untrusted input in the delete_associated_files function. This makes it possible for unauthenticated attackers to…

  • CVE-2023-39920HigDec 13, 2024
    risk 0.49cvss 7.5epss 0.01

    Missing Authorization vulnerability in Themeisle Redirection for Contact Form 7 wpcf7-redirect allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Redirection for Contact Form 7: from n/a through <= 2.9.2.

  • CVE-2023-23990HigMay 17, 2024
    risk 0.49cvss 7.6epss 0.01

    Improper Privilege Management vulnerability in Qube One Ltd. Redirection for Contact Form 7 wpcf7-redirect allows Privilege Escalation.This issue affects Redirection for Contact Form 7: from n/a through 2.7.0.

  • CVE-2021-36913HigOct 11, 2022
    risk 0.49cvss 7.5epss 0.01

    Unauthenticated Options Change and Content Injection vulnerability in Qube One Redirection for Contact Form 7 plugin <= 2.4.0 at WordPress allows attackers to change options and inject scripts into the footer HTML. Requires an additional extension (plugin) AccessiBe.

  • CVE-2021-24278HigMay 14, 2021
    risk 0.49cvss 7.5epss 0.07

    In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, unauthenticated users can use the wpcf7r_get_nonce AJAX action to retrieve a valid nonce for any WordPress action/function.

  • CVE-2026-23970HigJun 15, 2026
    risk 0.46cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in Redirection for Contact Form 7 <= 3.2.8 versions.

  • CVE-2025-14800HigDec 21, 2025
    risk 0.46cvss 8.1epss 0.00

    The Redirection for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'move_file_to_upload' function in all versions up to, and including, 3.2.7. This makes it possible for unauthenticated attackers to copy…

  • CVE-2025-9562MedOct 18, 2025
    risk 0.42cvss 6.4epss 0.00

    The Redirection for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's qs_date shortcode in all versions up to, and including, 3.2.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes…

  • CVE-2021-24279MedMay 14, 2021
    risk 0.42cvss 6.5epss 0.01

    In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, low level users, such as subscribers, could use the import_from_debug AJAX action to install any plugin from the WordPress repository.

  • CVE-2021-24282MedMay 14, 2021
    risk 0.41cvss 6.3epss 0.01

    In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, any authenticated user, such as a subscriber, could use the various AJAX actions in the plugin to do a variety of things. For example, an attacker could use wpcf7r_reset_settings to reset the plugin’s…

  • CVE-2022-0250MedJul 4, 2022
    risk 0.40cvss 6.1epss 0.02

    The Redirection for Contact Form 7 WordPress plugin before 2.5.0 does not escape a link generated before outputting it in an attribute, leading to a Reflected Cross-Site Scripting

  • CVE-2026-80439MedSep 6, 2026
    risk 0.31cvss 4.8epss 0.00

    The Redirection for Contact Form 7 WordPress plugin from 2.2.7 before 3.2.11 does not prevent shortcodes in submitted form values from being executed when it substitutes those values into an action's settings and then processes those settings for shortcodes, allowing…

  • CVE-2021-24281MedMay 14, 2021
    risk 0.28cvss 4.3epss 0.01

    In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, any authenticated user, such as a subscriber, could use the delete_action_post AJAX action to delete any post on a target site.