Security
Loading…

CVE-2026-80439

MEDIUMCVSS 4.8
Description

The Redirection for Contact Form 7 WordPress plugin from 2.2.7 before 3.2.11 does not prevent shortcodes in submitted form values from being executed when it substitutes those values into an action's settings and then processes those settings for shortcodes, allowing unauthenticated users to run any shortcode registered on the site and read its output.

Timeline
Published:September 6th, 2026 10:17 AM
Last modified:September 6th, 2026 11:18 AM
CVSS Scoring

CVSS v3: 4.8 (MEDIUM)

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N

Weaknesses (CWE)
References & Reports
Advisories, patches, and third-party reports

Source: NIST NVD · Data may lag official sources by up to one minute