Record summary

CVE-2021-24278 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, unauthenticated users can use the wpcf7r_get_nonce AJAX action to retrieve a valid nonce for any WordPress action/function.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jan 29, 2023 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

2
ProductSourceVersion rangeStatus
CVE List2.3.4 to < 2.3.4affected
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryHIGHWordPress Contact Form 7 <2.3.4 - Arbitrary Nonce GenerationCVSS 7.5

WordPress Contact Form 7 before version 2.3.4 allows unauthenticated users to use the wpcf7r_get_nonce AJAX action to retrieve a valid nonce for any WordPress action/function.

Impact

Attackers can exploit this vulnerability to perform actions on behalf of authenticated users, leading to potential data breaches or unauthorized access.

Remediation

Update WordPress Contact Form 7 plugin to version 2.3.4 or later to fix the Arbitrary Nonce Generation vulnerability.

WeaknessesCWE-863
Authors2rs3c
Template tagscve2021cvewordpresswp-pluginwpscanquerysolvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:querysol:redirection_for_contact_form_7:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

3