Extension WordPress
Vulnérabilités Redirection for Contact Form 7
Cette page rassemble les failles publiées pour Redirection for Contact Form 7, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Redirection for Contact Form 7
17 fiches
Redirection for Contact Form 7 <= 3.2.8 – Unauthenticated Stored Cross-Site Scripting
The Redirection for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.2.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…
*-3.2.8
3.2.9
13/05/2026
Redirection for Contact Form 7 <= 3.2.7 – Unauthenticated Arbitrary File Copy via move_file_to_upload
The Redirection for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'move_file_to_upload' function in all versions up to, and including, 3.2.7. This makes it possible for…
*-3.2.7
3.2.8
20/12/2025
Redirection for Contact Form 7 <= 3.2.6 – Authenticated (Contributor+) Stored Cross-Site Scripting via qs_date Shortcode
The Redirection for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's qs_date shortcode in all versions up to, and including, 3.2.6 due to insufficient input sanitization and output escaping on user…
*-3.2.6
3.2.7
17/10/2025
Redirection for Contact Form 7 <= 3.2.4 – Unauthenticated Arbitrary File Deletion
The Redirection for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_associated_files function in all versions up to, and including, 3.2.4. This makes it possible for…
*-3.2.4
3.2.5
19/08/2025
Redirection for Contact Form 7 <= 3.2.4 – Unauthenticated PHP Object Injection via PHAR Deserialization
The Redirection for Contact Form 7 plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.2.4 via deserialization of untrusted input in the delete_associated_files function. This makes it possible for unauthenticated…
*-3.2.4
3.2.5
19/08/2025
Redirection for Contact Form 7 <= 3.2.4 – Unauthenticated PHP Object Injection
The Redirection for Contact Form 7 plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.2.4 via deserialization of untrusted input in the get_lead_fields function. This makes it possible for unauthenticated…
*-3.2.4
3.2.5
19/08/2025
Redirection for Contact Form 7 <= 2.9.2 – Missing Authorization
The Redirection for Contact Form 7 plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the export_current_filtered_view() function hooked via admin_init in versions up to, and including, 2.9.2. This makes…
*-2.9.2
3.0.0
03/10/2023
Freemius SDK <= 2.5.9 – Reflected Cross-Site Scripting via fs_request_get
The Freemius SDK for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘fs_request_get’ function in versions up to, and including, 2.5.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…
2.3.7-2.8.0
2.9.0
18/07/2023
Redirection for Contact Form 7 <= 2.7.0 – Authenticated(Editor+) Privilege Escalation
The Redirection for Contact Form 7 plugin is vulnerable to Authenticated Privilege Escalation in versions up to, and including, 2.7.0 due to the ability to update usermeta information. This allows authenticated attackers with Editor-level permissions and above to…
*-2.7.0
2.8.0
06/02/2023
Redirection for Contact Form 7 <= 2.4.0 – Missing Authorization
The Redirection for Contact Form 7 plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on an unknown function in versions up to, and including, 2.4.0. This makes it possible for unauthenticated attackers…
*-2.4.0
2.7.0
29/09/2022
Redirection for Contact Form 7 <= 2.4.0 – Reflected Cross-Site Scripting
The Redirection for Contact Form 7 WordPress plugin before 2.5.0 does not escape a link generated before outputting it in an attribute, leading to a Reflected Cross-Site Scripting
*-2.4.0
2.5.0
07/03/2022
Freemius SDK <= 2.4.2 – Missing Authorization Checks
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions…
[*, 2.5.0)
2.5.0
04/03/2022
Redirection for Contact Form 7 <= 2.3.3 – Authenticated Arbitrary Post Deletion
In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, any authenticated user, such as a subscriber, could use the delete_action_post AJAX action to delete any post on a target site.
[*, 2.3.4)
2.3.4
20/04/2021
Redirection for Contact Form 7 <= 2.3.3 – Unprotected AJAX Actions
In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, any authenticated user, such as a subscriber, could use the various AJAX actions in the plugin to do a variety of things. For example, an attacker could…
[*, 2.3.4)
2.3.4
20/04/2021
Redirection for Contact Form 7 <= 2.3.3 – Authenticated PHP Object Injection
In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, any authenticated user, such as a subscriber, could use the import_from_debug AJAX action to inject PHP objects.
[*, 2.3.4)
2.3.4
20/04/2021
Redirection for Contact Form 7 <= 2.3.3 – Unauthenticated Arbitrary Nonce Generation
In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, unauthenticated users can use the wpcf7r_get_nonce AJAX action to retrieve a valid nonce for any WordPress action/function.
[*, 2.3.4)
2.3.4
20/04/2021
Redirection for Contact Form 7 <= 2.3.3 – Authenticated Arbitrary Plugin Installation
In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, low level users, such as subscribers, could use the import_from_debug AJAX action to install any plugin from the WordPress repository.
[*, 2.3.4)
2.3.4
20/04/2021
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.