First published: Fri Dec 13 2024(Updated: )
Missing Authorization vulnerability in Themeisle Redirection for Contact Form 7 allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Redirection for Contact Form 7: from n/a through 2.9.2.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Redirection for Contact Form 7 | <=2.9.2 | |
Redirection for Contact Form 7 | <=2.9.2 |
Update the WordPress Redirection for Contact Form 7 plugin to the latest available version (at least 3.0.0).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-39920 is classified as a Missing Authorization vulnerability that can lead to unauthorized access due to incorrectly configured access controls.
To fix CVE-2023-39920, update the Redirection for Contact Form 7 plugin to a version above 2.9.2 where this vulnerability has been addressed.
All versions of Redirection for Contact Form 7 up to and including 2.9.2 are affected by CVE-2023-39920.
CVE-2023-39920 can be exploited by an attacker taking advantage of improperly configured access control, potentially allowing them to perform unauthorized actions.
CVE-2023-39920 is a Missing Authorization vulnerability, specifically related to access control issues in the Redirection for Contact Form 7 plugin.