CVE-2021-24282: Redirection for Contact Form 7 < 2.3.4 - Unprotected AJAX Actions
Published May 14, 2021
·Updated
In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, any authenticated user, such as a subscriber, could use the various AJAX actions in the plugin to do a variety of things. For example, an attacker could use wpcf7rresetsettings to reset the plugin’s settings, wpcf7raddaction to add actions to a form, and more.
Affected Software
1 affected component
Querysol Redirection For Contact Form 7 Wordpress<2.3.4
Event History
May 14, 2021
CVE Published
via MITRE·11:38 AM
Data Sourced
via MITRE·11:38 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-24282?
CVE-2021-24282 is rated as a high severity vulnerability.
2
How do I fix CVE-2021-24282?
To fix CVE-2021-24282, update the Redirection for Contact Form 7 plugin to version 2.3.4 or later.
3
Who is affected by CVE-2021-24282?
CVE-2021-24282 affects all versions of the Redirection for Contact Form 7 plugin prior to 2.3.4.
4
What type of vulnerability is CVE-2021-24282?
CVE-2021-24282 is an authenticated AJAX action misuse vulnerability.
5
Can an unauthenticated user exploit CVE-2021-24282?
No, only authenticated users such as subscribers can exploit CVE-2021-24282.