CVE-2021-24278: Redirection for Contact Form 7 < 2.3.4 - Unauthenticated Arbitrary Nonce Generation
Published May 14, 2021
·Updated
In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, unauthenticated users can use the wpcf7rgetnonce AJAX action to retrieve a valid nonce for any WordPress action/function.
Affected Software
1 affected component
Querysol Redirection For Contact Form 7 Wordpress<2.3.4
Event History
May 14, 2021
CVE Published
via MITRE·11:38 AM
Data Sourced
via MITRE·11:38 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-24278?
CVE-2021-24278 is considered a high-severity vulnerability that allows unauthenticated users to retrieve a valid nonce.
2
How do I fix CVE-2021-24278?
To fix CVE-2021-24278, update the Redirection for Contact Form 7 plugin to version 2.3.4 or later.
3
Who is affected by CVE-2021-24278?
CVE-2021-24278 affects users of the Redirection for Contact Form 7 plugin versions prior to 2.3.4.
4
What could an attacker do with CVE-2021-24278?
An attacker exploiting CVE-2021-24278 could use the retrieved nonce to perform unauthorized actions on behalf of legitimate users.
5
Is CVE-2021-24278 a common vulnerability?
CVE-2021-24278 is a known vulnerability that highlights the importance of keeping WordPress plugins updated.