CyberRota Analysis
AI-GeneratedThe Redirection for Contact Form 7 WordPress plugin versions prior to 3.2.11 are vulnerable to unauthorized shortcode execution, enabling unauthenticated users to manipulate form submissions and access potentially sensitive output. This vulnerability poses a medium risk, as it could lead to information disclosure or further exploitation of the site. WordPress site administrators using affected versions should prioritize updating the plugin to mitigate this risk.
Original NVD Description
The Redirection for Contact Form 7 WordPress plugin from 2.2.7 before 3.2.11 does not prevent shortcodes in submitted form values from being executed when it substitutes those values into an action's settings and then processes those settings for shortcodes, allowing unauthenticated users to run any shortcode registered on the site and read its output.