PT-2025-14202 · Unknown+1 · Contact Form 7+1

Published

2025-04-01

·

Updated

2025-04-03

·

CVE-2025-31821

CVSS v3.1

4.7

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Integration of Zoho CRM and Contact Form 7 versions 1.0.0 through 1.0.6
Description The issue is related to a URL Redirection to Untrusted Site, also known as an 'Open Redirect' vulnerability, in the formsintegrations Integration of Zoho CRM and Contact Form 7. This vulnerability allows phishing attacks.
Recommendations For versions 1.0.0 through 1.0.6, update to a version that contains a fix for this issue to prevent URL redirection to untrusted sites. As a temporary workaround, consider restricting access to the integration of Zoho CRM and Contact Form 7 to minimize the risk of phishing attacks.

Fix

Open Redirect

Weakness Enumeration

Related Identifiers

CVE-2025-31821

Affected Products

Contact Form 7
Zoho Crm