CVE-2021-24278
Redirection for Contact Form 7 < 2.3.4 - Unauthenticated Arbitrary Nonce Generation
Record summary
CVE-2021-24278 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.
Description
In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, unauthenticated users can use the wpcf7r_get_nonce AJAX action to retrieve a valid nonce for any WordPress action/function.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jan 29, 2023 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Redirection for Contact Form 7Browse Query Solutions / Redirection for Contact Form 7 | CVE List | 2.3.4 to < 2.3.4 | affected |
redirection_for_contact_form_7Browse querysol / redirection_for_contact_form_7 | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryHIGHWordPress Contact Form 7 <2.3.4 - Arbitrary Nonce GenerationCVSS 7.5
WordPress Contact Form 7 before version 2.3.4 allows unauthenticated users to use the wpcf7r_get_nonce AJAX action to retrieve a valid nonce for any WordPress action/function.
Impact
Attackers can exploit this vulnerability to perform actions on behalf of authenticated users, leading to potential data breaches or unauthorized access.
Remediation
Update WordPress Contact Form 7 plugin to version 2.3.4 or later to fix the Arbitrary Nonce Generation vulnerability.
Source: ProjectDiscovery