CVE Database and Vulnerability Search
Search CVE and GHSA vulnerability records by identifier, title, vendor, product, package, or CWE. Filter by severity, CISA KEV, ransomware association, linked artifacts, and Nuclei templates; sort by publication date, CVSS, or EPSS.
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2021-24280HIGH | Redirection for Contact Form 7 < 2.3.4 - Authenticated PHP Object InjectionIn the Redirection for Contact Form 7 WordPress plugin before 2.3.4, any authenticated user, such as a subscriber, could use the import_from_debug AJAX action to inject PHP objects. CWE-502May 14, 2021 | CVSS8.8v3.1 | EPSS1.97% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-24279MEDIUM | Redirection for Contact Form 7 < 2.3.4 - Authenticated Arbitrary Plugin InstallationIn the Redirection for Contact Form 7 WordPress plugin before 2.3.4, low level users, such as subscribers, could use the import_from_debug AJAX action to install any plugin from the WordPress repository. CWE-863May 14, 2021 | CVSS6.5v3.1 | EPSS0.831% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-24281MEDIUM | Redirection for Contact Form 7 < 2.3.4 - Authenticated Arbitrary Post DeletionIn the Redirection for Contact Form 7 WordPress plugin before 2.3.4, any authenticated user, such as a subscriber, could use the delete_action_post AJAX action to delete any post on a target site. CWE-863May 14, 2021 | CVSS4.3v3.1 | EPSS0.663% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-24282MEDIUM | Redirection for Contact Form 7 < 2.3.4 - Unprotected AJAX ActionsIn the Redirection for Contact Form 7 WordPress plugin before 2.3.4, any authenticated user, such as a subscriber, could use the various AJAX actions in the plugin to do a variety of things. For example, an attacker could use wpcf7r_reset_settings to reset the plugin’s settings, wpcf7r_add_action to add actions to a form, and more. CWE-863May 14, 2021 | CVSS6.3v3.1 | EPSS0.728% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-24278HIGH | Redirection for Contact Form 7 < 2.3.4 - Unauthenticated Arbitrary Nonce GenerationIn the Redirection for Contact Form 7 WordPress plugin before 2.3.4, unauthenticated users can use the wpcf7r_get_nonce AJAX action to retrieve a valid nonce for any WordPress action/function. | CVSS7.5v3.1 | EPSS7.36% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |