Query Solutions Vulnerabilities and Affected Products
Vulnerabilities associated with Redirection for Contact Form 7.
Products
Clear product- Redirection for Contact Form 75 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2021-24280HIGH | Redirection for Contact Form 7 < 2.3.4 - Authenticated PHP Object InjectionIn the Redirection for Contact Form 7 WordPress plugin before 2.3.4, any authenticated user, such as a subscriber, could use the import_from_debug AJAX action to inject PHP objects. CWE-502May 14, 2021 | CVSS8.8v3.1 | EPSS1.97% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-24279MEDIUM | Redirection for Contact Form 7 < 2.3.4 - Authenticated Arbitrary Plugin InstallationIn the Redirection for Contact Form 7 WordPress plugin before 2.3.4, low level users, such as subscribers, could use the import_from_debug AJAX action to install any plugin from the WordPress repository. CWE-863May 14, 2021 | CVSS6.5v3.1 | EPSS0.831% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-24281MEDIUM | Redirection for Contact Form 7 < 2.3.4 - Authenticated Arbitrary Post DeletionIn the Redirection for Contact Form 7 WordPress plugin before 2.3.4, any authenticated user, such as a subscriber, could use the delete_action_post AJAX action to delete any post on a target site. CWE-863May 14, 2021 | CVSS4.3v3.1 | EPSS0.663% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-24282MEDIUM | Redirection for Contact Form 7 < 2.3.4 - Unprotected AJAX ActionsIn the Redirection for Contact Form 7 WordPress plugin before 2.3.4, any authenticated user, such as a subscriber, could use the various AJAX actions in the plugin to do a variety of things. For example, an attacker could use wpcf7r_reset_settings to reset the plugin’s settings, wpcf7r_add_action to add actions to a form, and more. CWE-863May 14, 2021 | CVSS6.3v3.1 | EPSS0.728% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-24278HIGH | Redirection for Contact Form 7 < 2.3.4 - Unauthenticated Arbitrary Nonce GenerationIn the Redirection for Contact Form 7 WordPress plugin before 2.3.4, unauthenticated users can use the wpcf7r_get_nonce AJAX action to retrieve a valid nonce for any WordPress action/function. | CVSS7.5v3.1 | EPSS7.36% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |