Executive brief
The Redirection for Contact Form 7 plugin for WordPress, which allows site owners to redirect users after they submit a contact form, contains a security flaw. An attacker could use this vulnerability to inject malicious scripts into the website, which would then execute in the browser of other visitors. This could lead to unauthorized actions being performed on behalf of users, theft of session information, or redirection to malicious websites.
Technical details
A Cross-Site Scripting (XSS) vulnerability exists in the Redirection for Contact Form 7 plugin for WordPress due to improper neutralization of user-supplied input during web page generation (CWE-79). The flaw allows an unauthenticated remote attacker to inject arbitrary JavaScript or HTML payloads. Exploitation requires a victim to interact with a specially crafted link or page (User Interaction Required). Successful exploitation can lead to session hijacking, unauthorized administrative actions if a logged-in admin is targeted, or website defacement. The issue is addressed in version 3.2.9.
Affected products
- Query-Line Redirection for Contact Form 7 <= 3.2.8
Timeline
- 2025-12-17: other: Reported by JongHwan Shin
- 2026-05-13: advisory: Patchstack advisory published
- 2026-06-15: disclosed: NVD publication date