← WordPress Vulnerabilities
WordPress security by component

Redirection for Contact Form 7

Redirection for Contact Form 7 is a WordPress component with 9 published CVE records in this archive. The latest tracked vulnerability was published Jun 15, 2026; the highest CVE/CNA score is 8.8.

Plugin slug: wpcf7-redirect

CVE-2026-23970: Redirection for Contact Form 7: Cross-site scripting

Redirection for Contact Form 7 is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 3.2.8.

PublishedJun 15, 2026
Known safe version3.2.9
Safe version
Jun 15, 2026 CVE-2026-23970
Redirection for Contact Form 7: Cross-site scripting
Redirection for Contact Form 7 is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 3.2.8.
3.2.9
CVE7.1
NVDPending
Dec 21, 2025 CVE-2025-14800
Redirection for Contact Form 7: Dangerous file upload
Redirection for Contact Form 7 is affected by dangerous file upload. The vulnerable path is reachable without authentication. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise.
See mitigation notes
CVE8.1
NVDPending
Oct 18, 2025 CVE-2025-9562
Redirection for Contact Form 7: Cross-site scripting
Redirection for Contact Form 7 is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVDPending
Aug 20, 2025 CVE-2025-8289
Redirection for Contact Form 7: Code execution
Redirection for Contact Form 7 is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE7.5
NVDPending
Aug 20, 2025 CVE-2025-8145
Redirection for Contact Form 7: Code execution
Redirection for Contact Form 7 is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE8.8
NVDPending
Aug 20, 2025 CVE-2025-8141
Redirection for Contact Form 7: Code execution
Redirection for Contact Form 7 is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE8.8
NVDPending
Dec 13, 2024 CVE-2023-39920
Redirection for Contact Form 7: A security weakness
Redirection for Contact Form 7 is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.5
NVDPending
May 17, 2024 CVE-2023-23990
Redirection for Contact Form 7: Privilege escalation or authentication bypass
Redirection for Contact Form 7 is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE7.6
NVDPending
Oct 11, 2022 CVE-2021-36913
Wpcf7 Redirect: A security weakness
Wpcf7 Redirect is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.5
NVD7.5