Redirection for Contact Form 7
cpe:2.3:a:redirection-for-contact-form7:redirection_for_contact_form_7:*:*:*:*:wordpress:*:*
- <= 3.2.4
A PHP Object Injection vulnerability has been identified in the Redirection for Contact Form 7 WordPress plugin, affecting all versions through 3.2.4. The vulnerability arises from the deserialization of untrusted input in the 'get_lead_fields' function, allowing unauthenticated attackers to inject PHP objects. Exploitation of this vulnerability is facilitated by a PHP Object Injection chain within the Contact Form 7 plugin, which could lead to the deletion of arbitrary files. In certain server configurations, this vulnerability could also allow for Remote Code Execution.
Exploitation of this vulnerability could result in PHP Object Injection, with the potential for file deletion and, in some server environments, Remote Code Execution.
Users are advised to update the Redirection for Contact Form 7 plugin to version 3.2.5 or a newer patched version.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.