Impact
An unauthenticated cross‑site scripting flaw exists in the WordPress Redirection for Contact Form 7 plugin (versions 3.2.8 and earlier) that allows an attacker to inject arbitrary JavaScript into the redirect URL. This could enable the execution of malicious scripts in the browsers of anyone who visits the affected page, potentially leading to cookie theft, session hijacking, or other downstream attacks as described by CWE‑79.
Affected Systems
The vulnerability affects the Themeisle Redirection for Contact Form 7 plugin. All installations running version 3.2.8 or older are vulnerable; versions 3.2.9 and later contain the fix.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity, while the EPSS score of < 1% shows a very low probability of exploitation in the wild. The flaw is not yet listed in the CISA KEV catalog. Given that the bug is unauthenticated, the likely attack vector is a public HTTP request containing a malicious redirect value – for example, by manipulating a form’s redirect URL in a carried‑out contact‑form submission. No privileged access or special configuration is required to exploit the flaw.
OpenCVE Enrichment