PLUGIN SECURITY
Is Wpcf7 Redirect safe?
Redirect to any page or URL, execute scripts after submission, save data to the database, and unlock additional submission actions for Contact Form 7.
What this plugin does
- Slug:
wpcf7-redirect - Author: Themeisle
- 200000+ active installs
- 94/100 rating (275 reviews on wordpress.org)
- 5814925 all-time downloads
- On WordPress.org since 2017-08-12
cf7 redirectcontact form 7mailchimpredirectwebhook
Maintenance status
- Latest known version: 3.2.10
- Last updated: 2026-08-20 6:54pm GMT
- Tested up to WordPress: 7.1
- Max supported PHP (analyzed): 8.4
Known vulnerabilities
16 known CVEs on file for Wpcf7 Redirect.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2026-23970 | Redirection for Contact Form 7 [wpcf7-redirect] < 3.2.9 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | High 7.1 | < 3.2.9 | 3.2.9 | 2026-05-13 | ✓ fixed in latest |
| CVE-2025-14800 | Redirection for Contact Form 7 [wpcf7-redirect] < 3.2.8 | Unrestricted Upload of File with Dangerous Type | High 8.1 | < 3.2.8 | 3.2.8 | 2025-12-20 | ✓ fixed in latest |
| CVE-2023-39920 | Redirection for Contact Form 7 [wpcf7-redirect] < 3.0.0 | Missing Authorization | High 7.5 | < 3.0.0 | 3.0.0 | 2023-10-03 | ✓ fixed in latest |
| CVE-2023-33999 | Redirection for Contact Form 7 [wpcf7-redirect] < 2.9.2 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | High 7.1 | < 2.9.2 | 2.9.2 | 2023-07-18 | ✓ fixed in latest |
| CVE-2023-23990 | Redirection for Contact Form 7 [wpcf7-redirect] < 2.8.0 | Improper Privilege Management | High 7.6 | < 2.8.0 | 2.8.0 | 2023-02-06 | ✓ fixed in latest |
| CVE-2021-36913 | Redirection for Contact Form 7 [wpcf7-redirect] < 2.7.0 | Improper Access Control | High 7.5 | < 2.7.0 | 2.7.0 | 2022-09-29 | ✓ fixed in latest |
| CVE-2022-0250 | Redirection for Contact Form 7 [wpcf7-redirect] < 2.5.0 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 2.5.0 | 2.5.0 | 2022-03-07 | ✓ fixed in latest |
| — | Redirection for Contact Form 7 [wpcf7-redirect] < 2.5.0 | Missing Authorization | Medium 6.3 | < 2.5.0 | 2.5.0 | 2022-03-04 | ✓ fixed in latest |
+ 22 more known vulnerabilities
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| — | Redirection for Contact Form 7 [wpcf7-redirect] < 2.5.0 | — | Unknown | < 2.5.0 | 2.5.0 | 2022-02-28 | ✓ fixed in latest |
| — | Redirection for Contact Form 7 [wpcf7-redirect] < 2.5.0 | — | Unknown | < 2.5.0 | 2.5.0 | 2022-02-28 | ✓ fixed in latest |
| CVE-2021-24279 | Redirection for Contact Form 7 [wpcf7-redirect] < 2.3.4 | Incorrect Authorization | Medium 6.5 | < 2.3.4 | 2.3.4 | 2021-04-20 | ✓ fixed in latest |
| CVE-2021-24280 | Redirection for Contact Form 7 [wpcf7-redirect] < 2.3.4 | Deserialization of Untrusted Data | High 8.8 | < 2.3.4 | 2.3.4 | 2021-04-20 | ✓ fixed in latest |
| CVE-2021-24281 | Redirection for Contact Form 7 [wpcf7-redirect] < 2.3.4 | Incorrect Authorization | Medium 4.3 | < 2.3.4 | 2.3.4 | 2021-04-20 | ✓ fixed in latest |
| CVE-2021-24282 | Redirection for Contact Form 7 [wpcf7-redirect] < 2.3.4 | Incorrect Authorization | Medium 6.3 | < 2.3.4 | 2.3.4 | 2021-04-20 | ✓ fixed in latest |
| CVE-2021-24278 | Redirection for Contact Form 7 [wpcf7-redirect] < 2.3.4 | Incorrect Authorization | High 7.5 | < 2.3.4 | 2.3.4 | 2021-04-20 | ✓ fixed in latest |
| — | Redirection for Contact Form 7 [wpcf7-redirect] < 2.3.4 | — | Unknown | < 2.3.4 | 2.3.4 | 2021-04-20 | ✓ fixed in latest |
| — | Redirection for Contact Form 7 [wpcf7-redirect] < 2.3.4 | — | Unknown | < 2.3.4 | 2.3.4 | 2021-04-20 | ✓ fixed in latest |
| — | Redirection for Contact Form 7 [wpcf7-redirect] < 2.3.4 | — | Unknown | < 2.3.4 | 2.3.4 | 2021-04-20 | ✓ fixed in latest |
| — | Redirection for Contact Form 7 [wpcf7-redirect] < 2.3.4 | — | Unknown | < 2.3.4 | 2.3.4 | 2021-04-20 | ✓ fixed in latest |
| — | Redirection for Contact Form 7 [wpcf7-redirect] < 2.3.4 | — | Unknown | < 2.3.4 | 2.3.4 | 2021-04-20 | ✓ fixed in latest |
| — | Redirection for Contact Form 7 [wpcf7-redirect] < 3.2.5 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | High 8.8 | < 3.2.5 | 3.2.5 | 0000-00-00 | ✓ fixed in latest |
| — | Redirection for Contact Form 7 [wpcf7-redirect] < 3.2.5 | Deserialization of Untrusted Data | High 8.8 | < 3.2.5 | 3.2.5 | 0000-00-00 | ✓ fixed in latest |
| — | Redirection for Contact Form 7 [wpcf7-redirect] < 3.2.5 | Deserialization of Untrusted Data | High 7.5 | < 3.2.5 | 3.2.5 | 0000-00-00 | ✓ fixed in latest |
| — | Redirection for Contact Form 7 [wpcf7-redirect] < 3.2.7 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.4 | < 3.2.7 | 3.2.7 | 0000-00-00 | ✓ fixed in latest |
| — | Redirection for Contact Form 7 [wpcf7-redirect] < 2.5.0 | — | Unknown | < 2.5.0 | 2.5.0 | — | ✓ fixed in latest |
| — | Unauthorised AJAX Calls via Freemius | — | Unknown | < 2.5.0 | 2.5.0 | — | ✓ fixed in latest |
| CVE-2025-8145 | Redirection for Contact Form 7 < 3.2.5 - Unauthenticated PHP Object Injection | — | Unknown | < 3.2.5 | 3.2.5 | — | ✓ fixed in latest |
| CVE-2025-8141 | Redirection for Contact Form 7 < 3.2.5 - Unauthenticated Arbitrary File Deletion | — | Unknown | < 3.2.5 | 3.2.5 | — | ✓ fixed in latest |
| CVE-2025-8289 | Redirection for Contact Form 7 < 3.2.5 - Unauthenticated PHP Object Injection via PHAR Deserialization | — | Unknown | < 3.2.5 | 3.2.5 | — | ✓ fixed in latest |
| CVE-2025-9562 | Redirection for Contact Form 7 < 3.2.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via qs_date Shortcode | — | Unknown | < 3.2.7 | 3.2.7 | — | ✓ fixed in latest |
How to fix it
Keep Wpcf7 Redirect updated — 3.2.10 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
- Database Addon for Contact Form 7 – CFDB7 — 600000+ active installs — 100/100 (1874) — max PHP 8.4
- ReCaptcha v2 for Contact Form 7 — 200000+ active installs — 100/100 (89) — max PHP 8.4
- Conditional Fields for Contact Form 7 — 100000+ active installs — 96/100 (166) — max PHP 8.4
- DTX – Dynamic Text Extension for Contact Form 7 — 100000+ active installs — 94/100 (99)
- LukasApps CAPTCHA tools for Contact Form 7 — 100000+ active installs — 82/100 (48)
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.