CVE Database /
CVE-2026-23970
CVE · High
CVE-2026-23970 — Redirection for Contact Form 7 [wpcf7-redirect] < 3.2.9
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-23970
|
Redirection for Contact Form 7 [wpcf7-redirect] < 3.2.9 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
High
7.1
|
< 3.2.9
|
3.2.9 |
2026-05-13 |
—
|
CVE-2026-23970
The Redirection for Contact Form 7 plugin for WordPress contains a security flaw affecting versions prior to 3.2.8, allowing malicious code to be embedded into the website's content without proper filtering or encoding. This vulnerability enables unauthorized parties to inject executable scripts that will run whenever users access affected pages.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings