PT-2021-15821 · WordPress · Redirection For Contact Form 7

Chloe Chamberland

·

Published

2021-05-14

·

Updated

2021-05-17

·

CVE-2021-24281

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Redirection for Contact Form 7 WordPress plugin versions prior to 2.3.4
Description The issue allows any authenticated user to delete any post on a target site using the delete action post AJAX action.
Recommendations For versions prior to 2.3.4, update to version 2.3.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the delete action post AJAX action to prevent unauthorized post deletion.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-24281

Affected Products

Redirection For Contact Form 7