CVE-2021-24281: Redirection for Contact Form 7 < 2.3.4 - Authenticated Arbitrary Post Deletion
Published May 14, 2021
·Updated
In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, any authenticated user, such as a subscriber, could use the deleteactionpost AJAX action to delete any post on a target site.
Affected Software
1 affected component
Querysol Redirection For Contact Form 7 Wordpress<2.3.4
Event History
May 14, 2021
CVE Published
via MITRE·11:38 AM
Data Sourced
via MITRE·11:38 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-24281?
CVE-2021-24281 has a high severity rating as it allows authenticated users to delete any post on the site.
2
How do I fix CVE-2021-24281?
To fix CVE-2021-24281, update the Redirection for Contact Form 7 plugin to version 2.3.4 or later.
3
Who is affected by CVE-2021-24281?
Any site running the Redirection for Contact Form 7 plugin versions before 2.3.4 is affected by this vulnerability.
4
What type of users can exploit CVE-2021-24281?
Authenticated users, such as subscribers, can exploit CVE-2021-24281 to delete posts.
5
What actions can be performed due to CVE-2021-24281?
Due to CVE-2021-24281, an authenticated user can perform the delete_action_post AJAX action to delete posts.