CVE-2026-23970: WordPress Redirection for Contact Form 7 plugin <= 3.2.8 - Cross Site Scripting (XSS) vulnerability
Unauthenticated Cross Site Scripting (XSS) in Redirection for Contact Form 7 <= 3.2.8 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress/redirection-for-contact-form-7to a version that resolves this vulnerability.Fixed in 3.2.9
Event History
Frequently Asked Questions
What is the severity of CVE-2026-23970?
CVE-2026-23970 has a severity rating of 7.1, indicating a high risk for exploitation.
How do I fix CVE-2026-23970?
To fix CVE-2026-23970, update the Redirection for Contact Form 7 plugin to version 3.2.9 or later.
What type of vulnerability is CVE-2026-23970?
CVE-2026-23970 is a Cross Site Scripting (XSS) vulnerability affecting the Redirection for Contact Form 7 plugin.
Who is affected by CVE-2026-23970?
Anyone using the Redirection for Contact Form 7 plugin version 3.2.8 or earlier on their WordPress site is affected by CVE-2026-23970.
What scenarios could allow exploitation of CVE-2026-23970?
CVE-2026-23970 can be exploited by an unauthenticated user due to improper input validation in the plugin.