CVE-2021-24280: Redirection for Contact Form 7 < 2.3.4 - Authenticated PHP Object Injection
In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, any authenticated user, such as a subscriber, could use the importfromdebug AJAX action to inject PHP objects.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-24280?
CVE-2021-24280 has a high severity level due to the potential for PHP object injection by authenticated users.
How do I fix CVE-2021-24280?
To fix CVE-2021-24280, update the Redirection for Contact Form 7 plugin to version 2.3.4 or later.
Who is affected by CVE-2021-24280?
CVE-2021-24280 affects WordPress sites using the Redirection for Contact Form 7 plugin versions prior to 2.3.4.
What can an attacker do with CVE-2021-24280?
An attacker can exploit CVE-2021-24280 to inject PHP objects, potentially compromising the security of the affected WordPress site.
Is user authentication required to exploit CVE-2021-24280?
Yes, CVE-2021-24280 requires the attacker to be an authenticated user, such as a subscriber, to exploit the vulnerability.