CVE-2025-9562: Redirection for Contact Form 7 <= 3.2.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via qs_date Shortcode
The Redirection for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's qsdate shortcode in all versions up to, and including, 3.2.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9562?
CVE-2025-9562 is classified as a medium severity vulnerability due to the potential for stored cross-site scripting attacks.
How do I fix CVE-2025-9562?
To fix CVE-2025-9562, upgrade the Redirection for Contact Form 7 plugin to version 3.2.7 or later.
What impact does CVE-2025-9562 have on affected systems?
CVE-2025-9562 can allow attackers to execute malicious scripts in the context of an authenticated user, leading to data theft or user impersonation.
Which versions are affected by CVE-2025-9562?
All versions of the Redirection for Contact Form 7 plugin up to and including 3.2.6 are affected by CVE-2025-9562.
Is user input directly responsible for CVE-2025-9562?
Yes, insufficient input sanitization and output escaping of user-supplied attributes in the qs_date shortcode contribute to the vulnerability in CVE-2025-9562.