CVE · Medium

CVE-2021-24279 — Redirection for Contact Form 7 [wpcf7-redirect] < 2.3.4

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2021-24279 Redirection for Contact Form 7 [wpcf7-redirect] < 2.3.4 Incorrect Authorization Medium 6.5 < 2.3.4 2.3.4 2021-04-20

CVE-2021-24279

The Redirection for Contact Form 7 plugin prior to version 2.3.4 contained a vulnerability where users with low privileges, including subscribers, were able to exploit the import_from_debug AJAX function to install arbitrary plugins sourced from the WordPress repository.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.