S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-24278 Scanner

CVE-2021-24278 scanner - Unauthenticated Arbitrary Nonce Generation vulnerability in Query Solutions Redirection for Contact Form 7 plugin for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.9k
Times Used
continuous scan runs
4.2k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-24278
7.5
CVSS

In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, unauthenticated users can use the wpcf7r_get_nonce AJAX action to retrieve a valid nonce for any WordPress action/function.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Redirection for Contact Form 7by Query Solutions
AFFECTED< 2.3.4SAFE ✓≥ 2.3.4
Updated Aug 21, 2026View on NVD →
Detail

Query Solutions Redirection for Contact Form 7 is a popular WordPress plugin, used by many website administrators to redirect visitors to pages or URLs of their choice after filling out a contact form. The plugin is designed to help website owners improve customer engagement and increase conversions by redirecting visitors to relevant pages, such as thank you pages, after a successful form submission. 

However, the plugin was recently found to have a critical vulnerability, identified as CVE-2021-24278. This vulnerability allows unauthenticated users to retrieve a valid nonce for any WordPress action/function, using the wpcf7r_get_nonce AJAX action. Once this vulnerability is exploited, an attacker can gain access to sensitive information, modify website content, or even take over the entire website. 

If left unpatched, this vulnerability can lead to serious consequences for website owners, such as damage to their online reputation, loss of business, or even legal liabilities. It is therefore crucial to take steps to protect against this vulnerability and secure your website from potential attacks. 

At s4e.io, we offer pro features that can help you quickly and easily learn about vulnerabilities in your digital assets. Our platform provides comprehensive vulnerability scanning and reporting, helping you to stay one step ahead of threats and secure your digital assets from attack. With our advanced features and expert support, you can achieve a high level of security confidence and ensure your website remains secure from potential attacks.

 

REFERENCES

Solution Advice

Here are some precautions you can take to protect your website against the CVE-2021-24278 vulnerability:

  • Update the Redirection for Contact Form 7 plugin to the latest version as soon as possible, as this vulnerability has been patched in version 2.3.4 
  • Employ powerful security measures such as firewalls and intrusion detection systems, to detect any suspicious activity on your website 
  • Use strong and unique passwords for all users and backend access points 
  • Regularly backup your website data and ensure that data recovery measures are in place 
  • Engage with a professional security team to conduct security assessments and vulnerability testing 

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.