Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Redirection for Contact Form 7 — Vulnerabilities & Security Advisories 14

All 14 CVE vulnerabilities found in Redirection for Contact Form 7, with AI-generated Chinese analysis, references, and POCs.

This page documents known security vulnerabilities for the Redirection for Contact Form 7 WordPress plugin. It focuses on issues related to access control, input validation, and cross-site scripting weaknesses. The collected data encompasses advisory reports and security updates released between January 2020 and December 2023. This aggregation provides a comprehensive view of the security posture of this specific plugin over a four-year period. Users can utilize this resource to track the vendor's response to reported security incidents and monitor their disclosure timeline. The content allows security researchers to understand the prevalence and nature of specific weakness classes within this ecosystem. By examining the history of vulnerabilities, administrators can better assess the risk profile associated with this software component. The page serves as a reference for understanding past security flaws and their remediation efforts. It helps stakeholders identify patterns in the types of bugs that have affected the product. This information is crucial for maintaining the integrity and safety of WordPress sites that rely on Contact Form 7 extensions. The structured presentation of data facilitates easier analysis of security trends. Visitors can explore how the developer has addressed various security concerns over time. This historical context supports more informed decision-making regarding plugin updates and security configurations. The focus remains strictly on factual reporting of identified issues and their resolutions without subjective commentary.

Vendor: Query Solutions

CVE IDTitleCVSSSeverityPublished
CVE-2026-23970 WordPress Redirection for Contact Form 7 plugin <= 3.2.8 - Cross Site Scripting (XSS) vulnerability CWE-79 7.1 High2026-06-15
CVE-2025-14800 Redirection for Contact Form 7 <= 3.2.7 - Unauthenticated Arbitrary File Copy via move_file_to_upload CWE-434 8.1 High2025-12-21
CVE-2025-9562 Redirection for Contact Form 7 <= 3.2.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via qs_date Shortcode CWE-79 6.4 Medium2025-10-18
CVE-2025-8141 Redirection for Contact Form 7 <= 3.2.4 - Unauthenticated Arbitrary File Deletion CWE-22 8.8 High2025-08-20
CVE-2025-8145 Redirection for Contact Form 7 <= 3.2.4 - Unauthenticated PHP Object Injection CWE-502 8.8 High2025-08-20
CVE-2025-8289 Redirection for Contact Form 7 <= 3.2.4 - Unauthenticated PHP Object Injection via PHAR Deserialization CWE-502 7.5 High2025-08-20
CVE-2023-39920 WordPress Redirection for Contact Form 7 plugin <= 2.9.2 - Broken Access Control vulnerability CWE-862 7.5 High2024-12-13
CVE-2023-23990 WordPress Redirection for Contact Form 7 plugin <= 2.7.0 - Privilege Escalation vulnerability CWE-269 7.6 High2024-05-17
CVE-2022-0250 Redirection for Contact Form 7 < 2.5.0 - Reflected Cross-Site Scripting CWE-79 6.1 -2022-07-04
CVE-2021-24278 Redirection for Contact Form 7 < 2.3.4 - Unauthenticated Arbitrary Nonce Generation CWE-863 7.5 -2021-05-14
CVE-2021-24279 Redirection for Contact Form 7 < 2.3.4 - Authenticated Arbitrary Plugin Installation CWE-863 6.5 -2021-05-14
CVE-2021-24280 Redirection for Contact Form 7 < 2.3.4 - Authenticated PHP Object Injection CWE-502 8.8 -2021-05-14
CVE-2021-24281 Redirection for Contact Form 7 < 2.3.4 - Authenticated Arbitrary Post Deletion CWE-863 6.5 -2021-05-14
CVE-2021-24282 Redirection for Contact Form 7 < 2.3.4 - Unprotected AJAX Actions CWE-863 6.3 -2021-05-14

All 14 known CVE vulnerabilities affecting Redirection for Contact Form 7 with full Chinese analysis, references, and POCs where available.