CVE Database /
CVE-2021-24282
CVE · Medium
CVE-2021-24282 — Redirection for Contact Form 7 [wpcf7-redirect] < 2.3.4
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2021-24282
|
Redirection for Contact Form 7 [wpcf7-redirect] < 2.3.4 |
Incorrect Authorization |
Medium
6.3
|
< 2.3.4
|
2.3.4 |
2021-04-20 |
—
|
CVE-2021-24282
The Redirection for Contact Form 7 plugin before version 2.3.4 contained multiple AJAX endpoints that lacked proper authorization checks, allowing any logged-in user regardless of their role to perform administrative functions. An attacker with subscriber-level access could exploit these endpoints to reset plugin configurations, add arbitrary actions to contact forms, and execute other sensitive operations intended only for administrators.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings