CVE-2021-36913 – Redirection for Contact Form 7 <= 2.4.0 - Unauthenticated Options Change and Content Injection vulnerability
https://notcve.org/view.php?id=CVE-2021-36913
Unauthenticated Options Change and Content Injection vulnerability in Qube One Redirection for Contact Form 7 plugin <= 2.4.0 at WordPress allows attackers to change options and inject scripts into the footer HTML. Requires an additional extension (plugin) AccessiBe. Una vulnerabilidad de cambio de opciones sin autenticación e inyección de contenido en el plugin Qube One Redirection for Contact Form 7 versiones anteriores a 2.4.0 incluyéndola en WordPress, permite a atacantes cambiar opciones e inyectar scripts en el HTML del pie de página. Requiere una extensión adicional (plugin) AccessiBe The Redirection for Contact Form 7 plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on an unknown function in versions up to, and including, 2.4.0. This makes it possible for unauthenticated attackers to update the plugin's options. • https://patchstack.com/database/vulnerability/wpcf7-redirect/wordpress-redirection-for-contact-form-7-plugin-2-4-0-unauthenticated-options-change-vulnerability?_s_id=cve https://wordpress.org/plugins/wpcf7-redirect/#developers • CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') CWE-284: Improper Access Control CWE-862: Missing Authorization •
CVE-2022-0250 – Redirection for Contact Form 7 < 2.5.0 - Reflected Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2022-0250
The Redirection for Contact Form 7 WordPress plugin before 2.5.0 does not escape a link generated before outputting it in an attribute, leading to a Reflected Cross-Site Scripting El plugin Redirection for Contact Form 7 de WordPress versiones anteriores a 2.5.0, no escapa a un enlace generado antes de emitirlo en un atributo, conllevando a un ataque de tipo Cross-Site Scripting reflejado • https://wpscan.com/vulnerability/05700942-3143-4978-89eb-814ceff74867 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •