CVE-2024-4704: Contact Form 7 < 5.9.5 - Unauthenticated Open Redirect
Published Jun 27, 2024
·Updated
The Contact Form 7 WordPress plugin before 5.9.5 has an open redirect that allows an attacker to utilize a false URL and redirect to the URL of their choosing.
Affected Software
1 affected component
Rocklobster Contact Form 7 Wordpress<5.9.5
Event History
Jun 27, 2024
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·06:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-4704?
CVE-2024-4704 has been assessed as a medium severity vulnerability due to the potential for open redirect attacks.
2
How do I fix CVE-2024-4704?
To fix CVE-2024-4704, update the Contact Form 7 plugin to version 5.9.5 or later.
3
What impact does CVE-2024-4704 have on my website?
CVE-2024-4704 can allow attackers to redirect users to malicious websites, potentially leading to phishing attacks.
4
Which versions of Contact Form 7 are affected by CVE-2024-4704?
CVE-2024-4704 affects all versions of Contact Form 7 prior to 5.9.5.
5
Is CVE-2024-4704 a common vulnerability in WordPress plugins?
Open redirects, like the one in CVE-2024-4704, are a fairly common vulnerability in many web applications, including WordPress plugins.