WP Clinic
Entrar Registrarse

SEGURIDAD DE PLUGINS

¿Es seguro Wpcf7 Redirect?

Vulnerabilidades conocidas, compatibilidad con PHP y alternativas más seguras para el plugin de WordPress Wpcf7 Redirect — verificado contra la base de datos de seguridad local de WP Clinic.

Qué hace este plugin

  • Slug: wpcf7-redirect
  • 200000+ instalaciones activas

cf7 redirectcontact form 7mailchimpredirectwebhook

Estado de mantenimiento

  • Última versión conocida: 3.2.10
  • PHP máximo soportado (analizado): 8.4

Vulnerabilidades conocidas

15 CVEs conocidos registrados para Wpcf7 Redirect.

CVE Vulnerabilidad Tipo Gravedad Afectadas Corregido en Publicado Estado
CVE-2026-23970 Redirection for Contact Form 7 [wpcf7-redirect] < 3.2.9 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Alta 7,1 < 3.2.9 3.2.9 2026-05-13 ✓ corregido en la última versión
CVE-2025-14800 Redirection for Contact Form 7 [wpcf7-redirect] < 3.2.8 Carga de archivos sin restricción de tipo peligroso Alta 8,1 < 3.2.8 3.2.8 2025-12-20 ✓ corregido en la última versión
CVE-2023-39920 Redirection for Contact Form 7 [wpcf7-redirect] < 3.0.0 Falta de control de autorización Alta 7,5 < 3.0.0 3.0.0 2023-10-03 ✓ corregido en la última versión
CVE-2023-33999 Redirection for Contact Form 7 [wpcf7-redirect] < 2.9.2 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Alta 7,1 < 2.9.2 2.9.2 2023-07-18 ✓ corregido en la última versión
CVE-2023-23990 Redirection for Contact Form 7 [wpcf7-redirect] < 2.8.0 Gestión incorrecta de privilegios Alta 7,6 < 2.8.0 2.8.0 2023-02-06 ✓ corregido en la última versión
CVE-2021-36913 Redirection for Contact Form 7 [wpcf7-redirect] < 2.7.0 Control de acceso incorrecto Alta 7,5 < 2.7.0 2.7.0 2022-09-29 ✓ corregido en la última versión
CVE-2022-0250 Redirection for Contact Form 7 [wpcf7-redirect] < 2.5.0 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,1 < 2.5.0 2.5.0 2022-03-07 ✓ corregido en la última versión
Redirection for Contact Form 7 [wpcf7-redirect] < 2.5.0 Falta de control de autorización Media 6,3 < 2.5.0 2.5.0 2022-03-04 ✓ corregido en la última versión

CVE-2026-23970

The Redirection for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.2.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2025-14800

The Redirection for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'move_file_to_upload' function in all versions up to, and including, 3.2.7. This makes it possible for unauthenticated attackers to copy arbitrary files on the affected site's server. If 'allow_url_fopen' is set to 'On', it is possible to upload a remote file to the server.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2023-39920

Update the WordPress Redirection for Contact Form 7 plugin to the latest available version (at least 3.0.0). Nguyen Anh Tien discovered and reported this Broken Access Control vulnerability in WordPress Redirection for Contact Form 7 Plugin. A broken access control issue refers to a missing authorization, authentication or nonce token check in a function that could lead to an unprivileged user to executing a certain higher privileged action. This vulnerability has been fixed in version 3.0.0.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2023-33999

Update the plugin to the latest version. Rafie Muhammad (Patchstack) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Redirection for Contact Form 7 Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 2.9.2.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2023-23990

Update the WordPress Redirection for Contact Form 7 plugin to the latest available version (at least 2.8.0). Rafie Muhammad (Patchstack) discovered and reported this Privilege Escalation vulnerability in WordPress Redirection for Contact Form 7 Plugin. This could allow a malicious actor to escalate their low privileged account to something with higher privileges. After this they could take full control of the website. This vulnerability has been fixed in version 2.8.0.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2021-36913

The Redirection for Contact Form 7 plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on an unknown function in versions up to, and including, 2.4.0. This makes it possible for unauthenticated attackers to update the plugin's options.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2022-0250

The Redirection for Contact Form 7 WordPress plugin before 2.5.0 does not escape a link generated before outputting it in an attribute, leading to a Reflected Cross-Site Scripting

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

Redirection for Contact Form 7 [wpcf7-redirect] < 2.5.0

The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. Any WordPress plugin or theme running a version of Freemius less than 2.4.3 is vulnerable.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

+ 17 vulnerabilidades conocidas más
CVE Vulnerabilidad Tipo Gravedad Afectadas Corregido en Publicado Estado
Redirection for Contact Form 7 [wpcf7-redirect] < 2.5.0 Desconocido < 2.5.0 2.5.0 2022-02-28 ✓ corregido en la última versión
Redirection for Contact Form 7 [wpcf7-redirect] < 2.5.0 Desconocido < 2.5.0 2.5.0 2022-02-28 ✓ corregido en la última versión
CVE-2021-24279 Redirection for Contact Form 7 [wpcf7-redirect] < 2.3.4 Autorización incorrecta Media 6,5 < 2.3.4 2.3.4 2021-04-20 ✓ corregido en la última versión
CVE-2021-24280 Redirection for Contact Form 7 [wpcf7-redirect] < 2.3.4 Deserialización de datos no confiables Alta 8,8 < 2.3.4 2.3.4 2021-04-20 ✓ corregido en la última versión
CVE-2021-24281 Redirection for Contact Form 7 [wpcf7-redirect] < 2.3.4 Autorización incorrecta Media 4,3 < 2.3.4 2.3.4 2021-04-20 ✓ corregido en la última versión
CVE-2021-24282 Redirection for Contact Form 7 [wpcf7-redirect] < 2.3.4 Autorización incorrecta Media 6,3 < 2.3.4 2.3.4 2021-04-20 ✓ corregido en la última versión
CVE-2021-24278 Redirection for Contact Form 7 [wpcf7-redirect] < 2.3.4 Autorización incorrecta Alta 7,5 < 2.3.4 2.3.4 2021-04-20 ✓ corregido en la última versión
Redirection for Contact Form 7 [wpcf7-redirect] < 2.3.4 Desconocido < 2.3.4 2.3.4 2021-04-20 ✓ corregido en la última versión
Redirection for Contact Form 7 [wpcf7-redirect] < 2.3.4 Desconocido < 2.3.4 2.3.4 2021-04-20 ✓ corregido en la última versión
Redirection for Contact Form 7 [wpcf7-redirect] < 2.3.4 Desconocido < 2.3.4 2.3.4 2021-04-20 ✓ corregido en la última versión
Redirection for Contact Form 7 [wpcf7-redirect] < 2.3.4 Desconocido < 2.3.4 2.3.4 2021-04-20 ✓ corregido en la última versión
Redirection for Contact Form 7 [wpcf7-redirect] < 2.3.4 Desconocido < 2.3.4 2.3.4 2021-04-20 ✓ corregido en la última versión
CVE-2025-8141 Redirection for Contact Form 7 [wpcf7-redirect] < 3.2.5 Limitación incorrecta de una ruta a un directorio restringido (Path Traversal) Alta 8,8 < 3.2.5 3.2.5 0000-00-00 ✓ corregido en la última versión
CVE-2025-8145 Redirection for Contact Form 7 [wpcf7-redirect] < 3.2.5 Deserialización de datos no confiables Alta 8,8 < 3.2.5 3.2.5 0000-00-00 ✓ corregido en la última versión
CVE-2025-8289 Redirection for Contact Form 7 [wpcf7-redirect] < 3.2.5 Deserialización de datos no confiables Alta 7,5 < 3.2.5 3.2.5 0000-00-00 ✓ corregido en la última versión
Redirection for Contact Form 7 [wpcf7-redirect] < 3.2.7 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,4 < 3.2.7 3.2.7 0000-00-00 ✓ corregido en la última versión
Redirection for Contact Form 7 [wpcf7-redirect] < 2.5.0 Desconocido < 2.5.0 2.5.0 ✓ corregido en la última versión

Redirection for Contact Form 7 [wpcf7-redirect] < 2.5.0

Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability discovered in WordPress Redirection for Contact Form 7 plugin (versions < 2.5.0).

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

Redirection for Contact Form 7 [wpcf7-redirect] < 2.5.0

Sensitive Information Disclosure vulnerability discovered in WordPress Redirection for Contact Form 7 plugin (versions < 2.5.0).

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2021-24279

In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, low level users, such as subscribers, could use the import_from_debug AJAX action to install any plugin from the WordPress repository.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2021-24280

In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, any authenticated user, such as a subscriber, could use the import_from_debug AJAX action to inject PHP objects.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2021-24281

In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, any authenticated user, such as a subscriber, could use the delete_action_post AJAX action to delete any post on a target site.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2021-24282

In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, any authenticated user, such as a subscriber, could use the various AJAX actions in the plugin to do a variety of things. For example, an attacker could use wpcf7r_reset_settings to reset the plugin’s settings, wpcf7r_add_action to add actions to a form, and more.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2021-24278

In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, unauthenticated users can use the wpcf7r_get_nonce AJAX action to retrieve a valid nonce for any WordPress action/function.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

Redirection for Contact Form 7 [wpcf7-redirect] < 2.3.4

Unauthenticated Arbitrary Nonce Generation vulnerability discovered by WordFence in WordPress Redirection for Contact Form 7 plugin (versions <= 2.3.3).

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

Redirection for Contact Form 7 [wpcf7-redirect] < 2.3.4

Authenticated Arbitrary Plugin Installation vulnerability discovered by WordFence in WordPress Redirection for Contact Form 7 plugin (versions <= 2.3.3).

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

Redirection for Contact Form 7 [wpcf7-redirect] < 2.3.4

Authenticated PHP Object Injection vulnerability discovered by WordFence in WordPress Redirection for Contact Form 7 plugin (versions <= 2.3.3).

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

Redirection for Contact Form 7 [wpcf7-redirect] < 2.3.4

Authenticated Arbitrary Post Deletion vulnerability discovered by WordFence in WordPress Redirection for Contact Form 7 plugin (versions <= 2.3.3).

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

Redirection for Contact Form 7 [wpcf7-redirect] < 2.3.4

Unprotected AJAX Actions vulnerability discovered by WordFence in WordPress Redirection for Contact Form 7 plugin (versions <= 2.3.3).

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2025-8141

The Redirection for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_associated_files function in all versions up to, and including, 3.2.4. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2025-8145

The Redirection for Contact Form 7 plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.2.4 via deserialization of untrusted input in the get_lead_fields function. This makes it possible for unauthenticated attackers to inject a PHP Object. The additional presence of a POP chain in a Contact Form 7 plugin allows attackers to delete arbitrary files. Additionally, in certain server configurations, Remote Code Execution is possible

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2025-8289

The Redirection for Contact Form 7 plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.2.4 via deserialization of untrusted input in the delete_associated_files function. This makes it possible for unauthenticated attackers to inject a PHP Object. This vulnerability may be exploited by unauthenticated attackers when a form is present on the site with a file upload action, and doesn't affect sites with PHP version > 8. This vulnerability also requires the 'Redirection For Contact Form 7 Extension - Create Post' extension to be installed and activated in order to be exploited. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target system, it may allow the attacker to perform actions like delete arbitrary files, retrieve sensitive data, or execute code depending on the POP chain present. We confirmed there is a usable gadget in Contact Form 7 plugin that makes arbitrary file deletion possible when installed with this plugin. Given Contact Form 7 is a requirement of this plugin, it is likely that any site with this plugin and the 'Redirection For Contact Form 7 Extension - Create Post' extension enabled is vulnerable to arbitrary file deletion.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Redirection for Contact Form 7 [wpcf7-redirect] < 3.2.7

The Redirection for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's qs_date shortcode in all versions up to, and including, 3.2.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

Redirection for Contact Form 7 [wpcf7-redirect] < 2.5.0

The plugins and themes use an insecure version of the Freemius Framework, which is lacking CSRF and/or authorisation in some of its AJAX actions. As a result, any authenticated users, such as subscriber could access the debug logs. Unauthenticated attackers could also make a logged in admin toggle the debug mode via a CSRF attack.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

Cómo solucionarlo

Mantén Wpcf7 Redirect actualizado — 3.2.10 es la última versión en wordpress.org, y cada CVE de arriba indica la versión exacta que lo corrigió ("Corregido en").

Este es el historial completo de vulnerabilidades conocidas del plugin, no un escaneo de una instalación específica — ejecuta un escaneo gratis de tu propio sitio para verificar tu versión instalada exacta.

Alternativas más seguras / más establecidas

Verifica tu propio sitio WordPress

Ejecuta un escaneo pasivo gratis ahora, o crea una cuenta gratuita e instala el plugin de WP Clinic para un escaneo profundo de toda tu cuenta de hosting y reparación asistida por IA.