PT-2021-15822 · WordPress · Redirection For Contact Form 7

Chloe Chamberland

·

Published

2021-05-14

·

Updated

2021-05-17

·

CVE-2021-24282

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Redirection for Contact Form 7 versions prior to 2.3.4
Description The issue allows any authenticated user, such as a subscriber, to utilize various AJAX actions within the plugin. This enables an attacker to perform several actions, for example, using wpcf7r reset settings to reset the plugin's settings or wpcf7r add action to add actions to a form.
Recommendations For versions prior to 2.3.4, update to version 2.3.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the AJAX actions wpcf7r reset settings and wpcf7r add action to prevent unauthorized modifications.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-24282

Affected Products

Redirection For Contact Form 7