CVE · Medium

CVE-2021-24281 — Redirection for Contact Form 7 [wpcf7-redirect] < 2.3.4

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2021-24281 Redirection for Contact Form 7 [wpcf7-redirect] < 2.3.4 Incorrect Authorization Medium 4.3 < 2.3.4 2.3.4 2021-04-20

CVE-2021-24281

The Redirection for Contact Form 7 plugin prior to version 2.3.4 contained a vulnerability that allowed users with any authentication level, including those with subscriber access, to remove arbitrary posts from a website through the delete_action_post AJAX function. This flaw could be exploited to delete posts without proper authorization checks.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.