PLUGIN SECURITY

Is Wpcf7 Redirect safe?

Redirect to any page or URL, execute scripts after submission, save data to the database, and unlock additional submission actions for Contact Form 7.

What this plugin does

  • Slug: wpcf7-redirect
  • Author: Themeisle
  • 200000+ active installs
  • 94/100 rating (275 reviews on wordpress.org)
  • 5814925 all-time downloads
  • On WordPress.org since 2017-08-12

cf7 redirectcontact form 7mailchimpredirectwebhook

Maintenance status

  • Latest known version: 3.2.10
  • Last updated: 2026-08-20 6:54pm GMT
  • Tested up to WordPress: 7.1
  • Max supported PHP (analyzed): 8.4

Known vulnerabilities

16 known CVEs on file for Wpcf7 Redirect.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-23970 Redirection for Contact Form 7 [wpcf7-redirect] < 3.2.9 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') High 7.1 < 3.2.9 3.2.9 2026-05-13 ✓ fixed in latest
CVE-2025-14800 Redirection for Contact Form 7 [wpcf7-redirect] < 3.2.8 Unrestricted Upload of File with Dangerous Type High 8.1 < 3.2.8 3.2.8 2025-12-20 ✓ fixed in latest
CVE-2023-39920 Redirection for Contact Form 7 [wpcf7-redirect] < 3.0.0 Missing Authorization High 7.5 < 3.0.0 3.0.0 2023-10-03 ✓ fixed in latest
CVE-2023-33999 Redirection for Contact Form 7 [wpcf7-redirect] < 2.9.2 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') High 7.1 < 2.9.2 2.9.2 2023-07-18 ✓ fixed in latest
CVE-2023-23990 Redirection for Contact Form 7 [wpcf7-redirect] < 2.8.0 Improper Privilege Management High 7.6 < 2.8.0 2.8.0 2023-02-06 ✓ fixed in latest
CVE-2021-36913 Redirection for Contact Form 7 [wpcf7-redirect] < 2.7.0 Improper Access Control High 7.5 < 2.7.0 2.7.0 2022-09-29 ✓ fixed in latest
CVE-2022-0250 Redirection for Contact Form 7 [wpcf7-redirect] < 2.5.0 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 2.5.0 2.5.0 2022-03-07 ✓ fixed in latest
Redirection for Contact Form 7 [wpcf7-redirect] < 2.5.0 Missing Authorization Medium 6.3 < 2.5.0 2.5.0 2022-03-04 ✓ fixed in latest
+ 22 more known vulnerabilities
CVE Vulnerability Type Severity Affected Fixed in Published Status
Redirection for Contact Form 7 [wpcf7-redirect] < 2.5.0 Unknown < 2.5.0 2.5.0 2022-02-28 ✓ fixed in latest
Redirection for Contact Form 7 [wpcf7-redirect] < 2.5.0 Unknown < 2.5.0 2.5.0 2022-02-28 ✓ fixed in latest
CVE-2021-24279 Redirection for Contact Form 7 [wpcf7-redirect] < 2.3.4 Incorrect Authorization Medium 6.5 < 2.3.4 2.3.4 2021-04-20 ✓ fixed in latest
CVE-2021-24280 Redirection for Contact Form 7 [wpcf7-redirect] < 2.3.4 Deserialization of Untrusted Data High 8.8 < 2.3.4 2.3.4 2021-04-20 ✓ fixed in latest
CVE-2021-24281 Redirection for Contact Form 7 [wpcf7-redirect] < 2.3.4 Incorrect Authorization Medium 4.3 < 2.3.4 2.3.4 2021-04-20 ✓ fixed in latest
CVE-2021-24282 Redirection for Contact Form 7 [wpcf7-redirect] < 2.3.4 Incorrect Authorization Medium 6.3 < 2.3.4 2.3.4 2021-04-20 ✓ fixed in latest
CVE-2021-24278 Redirection for Contact Form 7 [wpcf7-redirect] < 2.3.4 Incorrect Authorization High 7.5 < 2.3.4 2.3.4 2021-04-20 ✓ fixed in latest
Redirection for Contact Form 7 [wpcf7-redirect] < 2.3.4 Unknown < 2.3.4 2.3.4 2021-04-20 ✓ fixed in latest
Redirection for Contact Form 7 [wpcf7-redirect] < 2.3.4 Unknown < 2.3.4 2.3.4 2021-04-20 ✓ fixed in latest
Redirection for Contact Form 7 [wpcf7-redirect] < 2.3.4 Unknown < 2.3.4 2.3.4 2021-04-20 ✓ fixed in latest
Redirection for Contact Form 7 [wpcf7-redirect] < 2.3.4 Unknown < 2.3.4 2.3.4 2021-04-20 ✓ fixed in latest
Redirection for Contact Form 7 [wpcf7-redirect] < 2.3.4 Unknown < 2.3.4 2.3.4 2021-04-20 ✓ fixed in latest
Redirection for Contact Form 7 [wpcf7-redirect] < 3.2.5 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') High 8.8 < 3.2.5 3.2.5 0000-00-00 ✓ fixed in latest
Redirection for Contact Form 7 [wpcf7-redirect] < 3.2.5 Deserialization of Untrusted Data High 8.8 < 3.2.5 3.2.5 0000-00-00 ✓ fixed in latest
Redirection for Contact Form 7 [wpcf7-redirect] < 3.2.5 Deserialization of Untrusted Data High 7.5 < 3.2.5 3.2.5 0000-00-00 ✓ fixed in latest
Redirection for Contact Form 7 [wpcf7-redirect] < 3.2.7 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 3.2.7 3.2.7 0000-00-00 ✓ fixed in latest
Redirection for Contact Form 7 [wpcf7-redirect] < 2.5.0 Unknown < 2.5.0 2.5.0 ✓ fixed in latest
Unauthorised AJAX Calls via Freemius Unknown < 2.5.0 2.5.0 ✓ fixed in latest
CVE-2025-8145 Redirection for Contact Form 7 < 3.2.5 - Unauthenticated PHP Object Injection Unknown < 3.2.5 3.2.5 ✓ fixed in latest
CVE-2025-8141 Redirection for Contact Form 7 < 3.2.5 - Unauthenticated Arbitrary File Deletion Unknown < 3.2.5 3.2.5 ✓ fixed in latest
CVE-2025-8289 Redirection for Contact Form 7 < 3.2.5 - Unauthenticated PHP Object Injection via PHAR Deserialization Unknown < 3.2.5 3.2.5 ✓ fixed in latest
CVE-2025-9562 Redirection for Contact Form 7 < 3.2.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via qs_date Shortcode Unknown < 3.2.7 3.2.7 ✓ fixed in latest

How to fix it

Keep Wpcf7 Redirect updated — 3.2.10 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.