CVE-2026-80439 Details
Description
The Redirection for Contact Form 7 WordPress plugin from 2.2.7 before 3.2.11 does not prevent shortcodes in submitted form values from being executed when it substitutes those values into an action's settings and then processes those settings for shortcodes, allowing unauthenticated users to run any shortcode registered on the site and read its output.
A vulnerability exists in the Redirection for Contact Form 7 WordPress plugin, specifically in versions 2.2.7 prior to 3.2.11. The issue arises because the plugin does not properly sanitize shortcodes in form submissions before inserting them into action settings. This flaw allows unauthenticated users to execute any registered shortcode on the site and access its output. Exploitation requires a Contact Form 7 form with a text field and a Redirect action that includes the field in a custom URL.
Users are advised to update the Redirection for Contact Form 7 WordPress plugin to version 3.2.11 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 6, 2026CISA-ADP
Assessed Sep 6, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://wpscan.com/vulnerability/96562897-f18c-45d3-9f31-0e40e8df1383/ | [email protected] | AdvisoryExploitRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-74 | Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| Redirection for Contact Form 7 | >= 2.2.7, <= 3.2.10 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 6, 2026 | CVE Modified | CISA-ADP |
| Sep 6, 2026 | New CVE Received | [email protected] |
Volerion