plugin

Wpcf7 Redirect Vulnerabilities

42 known security issues reported for the Wpcf7 Redirect WordPress plugin. Most recent disclosed May 13, 2026.

8 high 9 medium

Running Wpcf7 Redirect on your site? Check whether your installed version is affected.

Scan your site free

Redirection for Contact Form 7 <= 3.2.8 - Unauthenticated Stored Cross-Site Scripting

high

The Redirection for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.2.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute wheneve...

CVSS:
7.2
Affected:
up to 3.2.8
Fixed in:
3.2.9
Disclosed:
May 13, 2026

CVE-2026-23970 on NVD →

Redirection for Contact Form 7 [wpcf7-redirect] < 3.2.8

unknown

[en] The Redirection for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'move_file_to_upload' function in all versions up to, and including, 3.2.7. This makes it possible for unauthenticated attackers to copy arbitrary files on the affected site's...

Affected:
up to 3.2.8
Fixed in:
3.2.8
Disclosed:
Dec 21, 2025

CVE-2025-14800 on NVD →

Redirection for Contact Form 7 <= 3.2.7 - Unauthenticated Arbitrary File Copy via move_file_to_upload

high

The Redirection for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'move_file_to_upload' function in all versions up to, and including, 3.2.7. This makes it possible for unauthenticated attackers to copy arbitrary files on the affected site's serve...

CVSS:
8.1
Affected:
up to 3.2.7
Fixed in:
3.2.8
Disclosed:
Dec 20, 2025

CVE-2025-14800 on NVD →

Redirection for Contact Form 7 <= 3.2.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via qs_date Shortcode

medium

The Redirection for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's qs_date shortcode in all versions up to, and including, 3.2.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,...

CVSS:
6.4
Affected:
up to 3.2.6
Fixed in:
3.2.7
Disclosed:
Oct 17, 2025

CVE-2025-9562 on NVD →

Redirection for Contact Form 7 <= 3.2.4 - Unauthenticated Arbitrary File Deletion

high

The Redirection for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_associated_files function in all versions up to, and including, 3.2.4. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, whi...

CVSS:
8.8
Affected:
up to 3.2.4
Fixed in:
3.2.5
Disclosed:
Aug 19, 2025

CVE-2025-8141 on NVD →

Redirection for Contact Form 7 <= 3.2.4 - Unauthenticated PHP Object Injection via PHAR Deserialization

high

The Redirection for Contact Form 7 plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.2.4 via deserialization of untrusted input in the delete_associated_files function. This makes it possible for unauthenticated attackers to inject a PHP Object. This vulnerability may be...

CVSS:
7.5
Affected:
up to 3.2.4
Fixed in:
3.2.5
Disclosed:
Aug 19, 2025

CVE-2025-8289 on NVD →

Redirection for Contact Form 7 <= 3.2.4 - Unauthenticated PHP Object Injection

high

The Redirection for Contact Form 7 plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.2.4 via deserialization of untrusted input in the get_lead_fields function. This makes it possible for unauthenticated attackers to inject a PHP Object. The additional presence of a POP...

CVSS:
8.8
Affected:
up to 3.2.4
Fixed in:
3.2.5
Disclosed:
Aug 19, 2025

CVE-2025-8145 on NVD →

Redirection for Contact Form 7 [wpcf7-redirect] < 3.0.0 (closed)

unknown

[en] Missing Authorization vulnerability in Themeisle Redirection for Contact Form 7 allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Redirection for Contact Form 7: from n/a through 2.9.2.

Affected:
up to 3.0.0
Fixed in:
3.0.0
Disclosed:
Dec 13, 2024

CVE-2023-39920 on NVD →

Redirection for Contact Form 7 [wpcf7-redirect] < 2.5.0 (closed)

unknown

[en] The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4....

Affected:
up to 2.5.0
Fixed in:
2.5.0
Disclosed:
Oct 16, 2024

CVE-2022-4974 on NVD →

Redirection for Contact Form 7 [wpcf7-redirect] < 2.8.0 (closed)

unknown

[en] Improper Privilege Management vulnerability in Qube One Ltd. Redirection for Contact Form 7 wpcf7-redirect allows Privilege Escalation.This issue affects Redirection for Contact Form 7: from n/a through 2.7.0.

Affected:
up to 2.8.0
Fixed in:
2.8.0
Disclosed:
May 17, 2024

CVE-2023-23990 on NVD →

Redirection for Contact Form 7 <= 2.9.2 - Missing Authorization

medium

The Redirection for Contact Form 7 plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the export_current_filtered_view() function hooked via admin_init in versions up to, and including, 2.9.2. This makes it possible for unauthenticated attackers to export lead data.

CVSS:
5.3
Affected:
up to 2.9.2
Fixed in:
3.0.0
Disclosed:
Oct 3, 2023

CVE-2023-39920 on NVD →

Freemius SDK <= 2.5.9 - Reflected Cross-Site Scripting via fs_request_get

medium

The Freemius SDK for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘fs_request_get’ function in versions up to, and including, 2.5.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute...

CVSS:
6.1
Affected:
2.3.7 – 2.8.0
Fixed in:
2.9.0
Disclosed:
Jul 18, 2023

CVE-2023-33999 on NVD →

Redirection for Contact Form 7 <= 2.7.0 - Authenticated(Editor+) Privilege Escalation

high

The Redirection for Contact Form 7 plugin is vulnerable to Authenticated Privilege Escalation in versions up to, and including, 2.7.0 due to the ability to update usermeta information. This allows authenticated attackers with Editor-level permissions and above to modify their permissions and grant themselves administra...

CVSS:
7.2
Affected:
up to 2.7.0
Fixed in:
2.8.0
Disclosed:
Feb 6, 2023

CVE-2023-23990 on NVD →

Redirection for Contact Form 7 [wpcf7-redirect] < 2.7.0 (closed)

unknown

[en] Unauthenticated Options Change and Content Injection vulnerability in Qube One Redirection for Contact Form 7 plugin <= 2.4.0 at WordPress allows attackers to change options and inject scripts into the footer HTML. Requires an additional extension (plugin) AccessiBe.

Affected:
up to 2.7.0
Fixed in:
2.7.0
Disclosed:
Oct 11, 2022

CVE-2021-36913 on NVD →

Redirection for Contact Form 7 <= 2.4.0 - Missing Authorization

medium

The Redirection for Contact Form 7 plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on an unknown function in versions up to, and including, 2.4.0. This makes it possible for unauthenticated attackers to update the plugin's options.

CVSS:
5.3
Affected:
up to 2.4.0
Fixed in:
2.7.0
Disclosed:
Sep 29, 2022

CVE-2021-36913 on NVD →

Redirection for Contact Form 7 [wpcf7-redirect] < 2.5.0 (closed)

unknown

[en] The Redirection for Contact Form 7 WordPress plugin before 2.5.0 does not escape a link generated before outputting it in an attribute, leading to a Reflected Cross-Site Scripting

Affected:
up to 2.5.0
Fixed in:
2.5.0
Disclosed:
Jul 4, 2022

CVE-2022-0250 on NVD →

Redirection for Contact Form 7 <= 2.4.0 - Reflected Cross-Site Scripting

medium

The Redirection for Contact Form 7 WordPress plugin before 2.5.0 does not escape a link generated before outputting it in an attribute, leading to a Reflected Cross-Site Scripting

CVSS:
6.1
Affected:
up to 2.4.0
Fixed in:
2.5.0
Disclosed:
Mar 7, 2022

CVE-2022-0250 on NVD →

Freemius SDK <= 2.4.2 - Missing Authorization Checks

medium

The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. An...

CVSS:
6.3
Affected:
up to 2.5.0
Fixed in:
2.5.0
Disclosed:
Mar 4, 2022

CVE-2022-4974 on NVD →

Redirection for Contact Form 7 [wpcf7-redirect] < 2.5.0 (closed)

unknown

The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. An...

Affected:
up to 2.5.0
Fixed in:
2.5.0
Disclosed:
Mar 4, 2022

Redirection for Contact Form 7 [wpcf7-redirect] < 2.5.0 (closed)

unknown

Sensitive Information Disclosure vulnerability discovered in WordPress Redirection for Contact Form 7 plugin (versions < 2.5.0).

Affected:
up to 2.5.0
Fixed in:
2.5.0
Disclosed:
Feb 28, 2022

Redirection for Contact Form 7 [wpcf7-redirect] < 2.5.0 (closed)

unknown

Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability discovered in WordPress Redirection for Contact Form 7 plugin (versions < 2.5.0).

Affected:
up to 2.5.0
Fixed in:
2.5.0
Disclosed:
Feb 28, 2022

Redirection for Contact Form 7 [wpcf7-redirect] < 2.3.4 (closed)

unknown

[en] In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, unauthenticated users can use the wpcf7r_get_nonce AJAX action to retrieve a valid nonce for any WordPress action/function.

Affected:
up to 2.3.4
Fixed in:
2.3.4
Disclosed:
May 14, 2021

CVE-2021-24278 on NVD →

Redirection for Contact Form 7 [wpcf7-redirect] < 2.3.4 (closed)

unknown

[en] In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, low level users, such as subscribers, could use the import_from_debug AJAX action to install any plugin from the WordPress repository.

Affected:
up to 2.3.4
Fixed in:
2.3.4
Disclosed:
May 14, 2021

CVE-2021-24279 on NVD →

Redirection for Contact Form 7 [wpcf7-redirect] < 2.3.4 (closed)

unknown

[en] In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, any authenticated user, such as a subscriber, could use the import_from_debug AJAX action to inject PHP objects.

Affected:
up to 2.3.4
Fixed in:
2.3.4
Disclosed:
May 14, 2021

CVE-2021-24280 on NVD →

Redirection for Contact Form 7 [wpcf7-redirect] < 2.3.4 (closed)

unknown

[en] In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, any authenticated user, such as a subscriber, could use the delete_action_post AJAX action to delete any post on a target site.

Affected:
up to 2.3.4
Fixed in:
2.3.4
Disclosed:
May 14, 2021

CVE-2021-24281 on NVD →

Redirection for Contact Form 7 [wpcf7-redirect] < 2.3.4 (closed)

unknown

[en] In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, any authenticated user, such as a subscriber, could use the various AJAX actions in the plugin to do a variety of things. For example, an attacker could use wpcf7r_reset_settings to reset the plugin’s settings, wpcf7r_add_action to add actions to...

Affected:
up to 2.3.4
Fixed in:
2.3.4
Disclosed:
May 14, 2021

CVE-2021-24282 on NVD →

Redirection for Contact Form 7 <= 2.3.3 - Authenticated PHP Object Injection

high

In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, any authenticated user, such as a subscriber, could use the import_from_debug AJAX action to inject PHP objects.

CVSS:
8.8
Affected:
up to 2.3.4
Fixed in:
2.3.4
Disclosed:
Apr 20, 2021

CVE-2021-24280 on NVD →

Redirection for Contact Form 7 <= 2.3.3 - Unauthenticated Arbitrary Nonce Generation

high

In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, unauthenticated users can use the wpcf7r_get_nonce AJAX action to retrieve a valid nonce for any WordPress action/function.

CVSS:
7.5
Affected:
up to 2.3.4
Fixed in:
2.3.4
Disclosed:
Apr 20, 2021

CVE-2021-24278 on NVD →

Redirection for Contact Form 7 <= 2.3.3 - Authenticated Arbitrary Plugin Installation

medium

In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, low level users, such as subscribers, could use the import_from_debug AJAX action to install any plugin from the WordPress repository.

CVSS:
6.5
Affected:
up to 2.3.4
Fixed in:
2.3.4
Disclosed:
Apr 20, 2021

CVE-2021-24279 on NVD →

Redirection for Contact Form 7 <= 2.3.3 - Unprotected AJAX Actions

medium

In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, any authenticated user, such as a subscriber, could use the various AJAX actions in the plugin to do a variety of things. For example, an attacker could use wpcf7r_reset_settings to reset the plugin’s settings, wpcf7r_add_action to add actions to a fo...

CVSS:
6.3
Affected:
up to 2.3.4
Fixed in:
2.3.4
Disclosed:
Apr 20, 2021

CVE-2021-24282 on NVD →

Redirection for Contact Form 7 <= 2.3.3 - Authenticated Arbitrary Post Deletion

medium

In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, any authenticated user, such as a subscriber, could use the delete_action_post AJAX action to delete any post on a target site.

CVSS:
4.3
Affected:
up to 2.3.4
Fixed in:
2.3.4
Disclosed:
Apr 20, 2021

CVE-2021-24281 on NVD →

Redirection for Contact Form 7 [wpcf7-redirect] < 2.3.4 (closed)

unknown

Unprotected AJAX Actions vulnerability discovered by WordFence in WordPress Redirection for Contact Form 7 plugin (versions <= 2.3.3).

Affected:
up to 2.3.4
Fixed in:
2.3.4
Disclosed:
Apr 20, 2021

Redirection for Contact Form 7 [wpcf7-redirect] < 2.3.4 (closed)

unknown

Authenticated Arbitrary Post Deletion vulnerability discovered by WordFence in WordPress Redirection for Contact Form 7 plugin (versions <= 2.3.3).

Affected:
up to 2.3.4
Fixed in:
2.3.4
Disclosed:
Apr 20, 2021

Redirection for Contact Form 7 [wpcf7-redirect] < 2.3.4 (closed)

unknown

Authenticated PHP Object Injection vulnerability discovered by WordFence in WordPress Redirection for Contact Form 7 plugin (versions <= 2.3.3).

Affected:
up to 2.3.4
Fixed in:
2.3.4
Disclosed:
Apr 20, 2021

Redirection for Contact Form 7 [wpcf7-redirect] < 2.3.4 (closed)

unknown

Authenticated Arbitrary Plugin Installation vulnerability discovered by WordFence in WordPress Redirection for Contact Form 7 plugin (versions <= 2.3.3).

Affected:
up to 2.3.4
Fixed in:
2.3.4
Disclosed:
Apr 20, 2021

Redirection for Contact Form 7 [wpcf7-redirect] < 2.3.4 (closed)

unknown

Unauthenticated Arbitrary Nonce Generation vulnerability discovered by WordFence in WordPress Redirection for Contact Form 7 plugin (versions <= 2.3.3).

Affected:
up to 2.3.4
Fixed in:
2.3.4
Disclosed:
Apr 20, 2021

Redirection for Contact Form 7 [wpcf7-redirect] < 2.5.0 (closed)

unknown

The plugins and themes use an insecure version of the Freemius Framework, which is lacking CSRF and/or authorisation in some of its AJAX actions. As a result, any authenticated users, such as subscriber could access the debug logs. Unauthenticated attackers could also make a logged in admin toggle the debug mode via a...

Affected:
up to 2.5.0
Fixed in:
2.5.0

Redirection for Contact Form 7 [wpcf7-redirect] < 2.9.2 (closed)

unknown

** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Affected:
up to 2.9.2
Fixed in:
2.9.2

CVE-2023-33999 on NVD →

Redirection for Contact Form 7 [wpcf7-redirect] < 3.2.5 (closed)

unknown
Affected:
up to 3.2.5
Fixed in:
3.2.5

CVE-2025-8141 on NVD →

Redirection for Contact Form 7 [wpcf7-redirect] < 3.2.5 (closed)

unknown
Affected:
up to 3.2.5
Fixed in:
3.2.5

CVE-2025-8145 on NVD →

Redirection for Contact Form 7 [wpcf7-redirect] < 3.2.5 (closed)

unknown
Affected:
up to 3.2.5
Fixed in:
3.2.5

CVE-2025-8289 on NVD →

Redirection for Contact Form 7 [wpcf7-redirect] < 3.2.7 (closed)

unknown
Affected:
up to 3.2.7
Fixed in:
3.2.7

CVE-2025-9562 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database