← WordPress Vulnerabilities
WordPress security by component

Redirection for Contact Form 7

Redirection for Contact Form 7 redirects visitors to selected pages or URLs after successful Contact Form 7 submissions.

Redirection for Contact Form 7 (redirection-for-contact-form-7) is a WordPress plugin with 7 published CVE records in this archive. The latest tracked vulnerability was published Sep 06, 2026; the highest published CVSS base score is 8.8.

Plugin slug: redirection-for-contact-form-7

CVE-2026-80439: Redirection for Contact Form 7 executes shortcodes supplied in form values

Redirection for Contact Form 7 from 2.2.7 through versions before 3.2.11 substitutes submitted form values into action settings and then processes those settings for shortcodes. An unauthenticated submitter can execute any shortcode registered on the site and read its output.

PublishedSep 06, 2026
Known safe version3.2.11
Published vulnerabilities for redirection-for-contact-form-7
Safe version
Sep 06, 2026 CVE-2026-80439
Redirection for Contact Form 7 executes shortcodes supplied in form values
Redirection for Contact Form 7 from 2.2.7 through versions before 3.2.11 substitutes submitted form values into action settings and then processes those settings for shortcodes. An unauthenticated submitter can execute any shortcode registered on the site and read its output.
3.2.11
CVE4.8
NVDPending
Jul 04, 2022 CVE-2022-0250
Redirection for Contact Form 7: Cross-site scripting
Redirection for Contact Form 7 is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVEPending
NVD6.1
May 14, 2021 CVE-2021-24282
Redirection for Contact Form 7: A security weakness
Redirection for Contact Form 7 is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVEPending
NVD6.3
May 14, 2021 CVE-2021-24281
Redirection for Contact Form 7: A security weakness
Redirection for Contact Form 7 is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVEPending
NVD4.3
May 14, 2021 CVE-2021-24280
Redirection for Contact Form 7: A security weakness
Redirection for Contact Form 7 is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVEPending
NVD8.8
May 14, 2021 CVE-2021-24279
Redirection for Contact Form 7: A security weakness
Redirection for Contact Form 7 is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVEPending
NVD6.5
May 14, 2021 CVE-2021-24278
Redirection for Contact Form 7: A security weakness
Redirection for Contact Form 7 is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVEPending
NVD7.5