cve/2021/CVE-2021-24282.md
2025-09-29 21:09:30 +02:00

18 lines
866 B
Markdown
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

### [CVE-2021-24282](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-24282)
![](https://img.shields.io/static/v1?label=Product&message=Redirection%20for%20Contact%20Form%207&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=2.3.4%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-863%20Incorrect%20Authorization&color=brightgreen)
### Description
In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, any authenticated user, such as a subscriber, could use the various AJAX actions in the plugin to do a variety of things. For example, an attacker could use wpcf7r_reset_settings to reset the plugins settings, wpcf7r_add_action to add actions to a form, and more.
### POC
#### Reference
No PoCs from references.
#### Github
- https://github.com/20142995/nuclei-templates