Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Redirection for Contact Form 7 — Vulnerabilities & Security Advisories 15

All 15 CVE vulnerabilities found in Redirection for Contact Form 7, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerability data for Redirection for Contact Form 7, a plugin developed by the plugin author, focusing specifically on security weaknesses associated with this component. The collection compiles recorded security flaws affecting the product, spanning its documented vulnerability history from the plugin’s initial release through the most recent advisory updates. Readers can use this page to track the vendor’s published security advisories, analyze the specific class of weaknesses affecting the plugin, and review the chronological history of reported vulnerabilities for Redirection for Contact Form 7.

Vendor: Query Solutions

CVE ID Title CVSS Severity Published
CVE-2026-80439 Redirection for Contact Form 7 2.2.7 - 3.2.10 - Unauthenticated Arbitrary Shortcode Execution via Action Setting Mail-Tags 4.8 Medium 2026-09-06
CVE-2026-23970 WordPress Redirection for Contact Form 7 plugin <= 3.2.8 - Cross Site Scripting (XSS) vulnerability CWE-79 7.1 High 2026-06-15
CVE-2025-14800 Redirection for Contact Form 7 <= 3.2.7 - Unauthenticated Arbitrary File Copy via move_file_to_upload CWE-434 8.1 High 2025-12-21
CVE-2025-9562 Redirection for Contact Form 7 <= 3.2.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via qs_date Shortcode CWE-79 6.4 Medium 2025-10-18
CVE-2025-8141 Redirection for Contact Form 7 <= 3.2.4 - Unauthenticated Arbitrary File Deletion CWE-22 8.8 High 2025-08-20
CVE-2025-8145 Redirection for Contact Form 7 <= 3.2.4 - Unauthenticated PHP Object Injection CWE-502 8.8 High 2025-08-20
CVE-2025-8289 Redirection for Contact Form 7 <= 3.2.4 - Unauthenticated PHP Object Injection via PHAR Deserialization CWE-502 7.5 High 2025-08-20
CVE-2023-39920 WordPress Redirection for Contact Form 7 plugin <= 2.9.2 - Broken Access Control vulnerability CWE-862 7.5 High 2024-12-13
CVE-2023-23990 WordPress Redirection for Contact Form 7 plugin <= 2.7.0 - Privilege Escalation vulnerability CWE-269 7.6 High 2024-05-17
CVE-2022-0250 Redirection for Contact Form 7 < 2.5.0 - Reflected Cross-Site Scripting CWE-79 6.1 - 2022-07-04
CVE-2021-24278 Redirection for Contact Form 7 < 2.3.4 - Unauthenticated Arbitrary Nonce Generation CWE-863 7.5 - 2021-05-14
CVE-2021-24279 Redirection for Contact Form 7 < 2.3.4 - Authenticated Arbitrary Plugin Installation CWE-863 6.5 - 2021-05-14
CVE-2021-24280 Redirection for Contact Form 7 < 2.3.4 - Authenticated PHP Object Injection CWE-502 8.8 - 2021-05-14
CVE-2021-24281 Redirection for Contact Form 7 < 2.3.4 - Authenticated Arbitrary Post Deletion CWE-863 6.5 - 2021-05-14
CVE-2021-24282 Redirection for Contact Form 7 < 2.3.4 - Unprotected AJAX Actions CWE-863 6.3 - 2021-05-14

All 15 known CVE vulnerabilities affecting Redirection for Contact Form 7 with full Chinese analysis, references, and POCs where available.