CVE-2025-14800
Redirection for Contact Form 7
Minimum safe version
3.2.8
Update to 3.2.8 or later to address 25 fixable vulnerabilities
Redirection for Contact Form 7 <= 3.2.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via qs_date Shortcode
Redirection for Contact Form 7 <= 3.2.4 - Unauthenticated PHP Object Injection via PHAR Deserialization
Redirection for Contact Form 7 <= 3.2.4 - Unauthenticated PHP Object Injection
WordPress Redirection for Contact Form 7 Plugin <= 3.2.4 is vulnerable to Arbitrary File Deletion
Freemius SDK <= 2.4.2 - Missing Authorization Checks
CVE-2023-39920
WordPress Redirection for Contact Form 7 Plugin < 2.9.2 is vulnerable to Cross Site Scripting (XSS)
CVE-2023-23990
Freemius SDK <= 2.4.2 - Missing Authorization Checks
CVE-2021-36913
Unauthorised AJAX Calls via Freemius
CVE-2022-0250
WordPress Redirection for Contact Form 7 plugin <= 2.3.3 - Unprotected AJAX Actions vulnerability
WordPress Redirection for Contact Form 7 plugin <= 2.3.3 - Authenticated Arbitrary Post Deletion vulnerability
WordPress Redirection for Contact Form 7 plugin <= 2.3.3 - Authenticated PHP Object Injection vulnerability
WordPress Redirection for Contact Form 7 plugin <= 2.3.3 - Authenticated Arbitrary Plugin Installation vulnerability
WordPress Redirection for Contact Form 7 plugin <= 2.3.3 - Unauthenticated Arbitrary Nonce Generation vulnerability
WordPress Redirection for Contact Form 7 plugin < 2.5.0 - Sensitive Information Disclosure vulnerability
WordPress Redirection for Contact Form 7 plugin < 2.5.0 - Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability
CVE-2021-24278
CVE-2021-24282
CVE-2021-24281
CVE-2021-24280
CVE-2021-24279