CVE-2025-31821: WordPress Integration of Zoho CRM and Contact Form 7 plugin <= 1.0.6 - Open Redirection Vulnerability
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in formsintegrations Integration of Zoho CRM and Contact Form 7 allows Phishing. This issue affects Integration of Zoho CRM and Contact Form 7: from n/a through 1.0.6.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-31821?
CVE-2025-31821 is categorized as a medium severity vulnerability due to its potential for phishing attacks through open redirection.
How does CVE-2025-31821 affect users?
Users are at risk of being redirected to untrusted sites, which can lead to phishing attempts and data theft.
How do I fix CVE-2025-31821?
To fix CVE-2025-31821, update the Integration of Zoho CRM and Contact Form 7 to version 1.0.7 or higher.
Which software versions are affected by CVE-2025-31821?
CVE-2025-31821 affects the versions of Integration of Zoho CRM and Contact Form 7 from n/a to 1.0.6.
What is the cause of CVE-2025-31821?
CVE-2025-31821 is caused by insufficient validation of URLs, allowing an attacker to redirect users to malicious sites.