First published: Tue Apr 01 2025(Updated: )
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in formsintegrations Integration of Zoho CRM and Contact Form 7 allows Phishing. This issue affects Integration of Zoho CRM and Contact Form 7: from n/a through 1.0.6.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress Integration of Zoho CRM and Contact Form 7 | >=n/a<=1.0.6 | |
Zoho CRM and Contact Form 7 Integration | <=1.0.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-31821 is categorized as a medium severity vulnerability due to its potential for phishing attacks through open redirection.
Users are at risk of being redirected to untrusted sites, which can lead to phishing attempts and data theft.
To fix CVE-2025-31821, update the Integration of Zoho CRM and Contact Form 7 to version 1.0.7 or higher.
CVE-2025-31821 affects the versions of Integration of Zoho CRM and Contact Form 7 from n/a to 1.0.6.
CVE-2025-31821 is caused by insufficient validation of URLs, allowing an attacker to redirect users to malicious sites.