CVE · High

CVE-2023-39920 — Redirection for Contact Form 7 [wpcf7-redirect] < 3.0.0

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-39920 Redirection for Contact Form 7 [wpcf7-redirect] < 3.0.0 Missing Authorization High 7.5 < 3.0.0 3.0.0 2023-10-03

CVE-2023-39920

The Redirection for Contact Form 7 plugin versions prior to 3.0.0 contain a broken access control flaw that allows unauthenticated or low-privilege users to perform actions normally restricted to higher-privilege roles. The vulnerability results from missing authorization checks and nonce verification in a plugin function. This issue was discovered by Nguyen Anh Tien and has been resolved in version 3.0.0 and later.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.