CVE · Medium

CVE-2021-24282 — Redirection for Contact Form 7 [wpcf7-redirect] < 2.3.4

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2021-24282 Redirection for Contact Form 7 [wpcf7-redirect] < 2.3.4 Incorrect Authorization Medium 6.3 < 2.3.4 2.3.4 2021-04-20

CVE-2021-24282

The Redirection for Contact Form 7 plugin before version 2.3.4 contained multiple AJAX endpoints that lacked proper authorization checks, allowing any logged-in user regardless of their role to perform administrative functions. An attacker with subscriber-level access could exploit these endpoints to reset plugin configurations, add arbitrary actions to contact forms, and execute other sensitive operations intended only for administrators.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.