S4E just found a high top 10 tcp port service scan
medium·Product Based Web Vulnerabilities·Updated Dec 3, 2024

CVE-2022-0250 Scanner

CVE-2022-0250 Scanner - Cross-Site Scripting vulnerability in Redirection for Contact Form 7

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.8k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-0250
6.1
CVSS

The Redirection for Contact Form 7 WordPress plugin before 2.5.0 does not escape a link generated before outputting it in an attribute, leading to a Reflected Cross-Site Scripting

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Redirection for Contact Form 7
AFFECTED< 2.5.0SAFE ✓≥ 2.5.0
Updated Aug 22, 2026View on NVD →
Detail

Redirection for Contact Form 7 is a WordPress plugin commonly used to add redirection capabilities to contact forms. It allows website owners to redirect users to specific URLs after form submissions. This plugin is widely adopted in WordPress websites for enhancing form functionality and improving user experience. By leveraging this tool, developers and site administrators can achieve seamless user navigation.

The vulnerability detected in this plugin is Cross-Site Scripting (XSS). This occurs because the plugin does not properly escape a generated link before outputting it in an attribute. This vulnerability allows attackers to inject malicious scripts into the web page, which are then executed in the context of a victim's browser.

The XSS vulnerability arises from improper handling of input in specific plugin endpoints, particularly when links are generated and displayed. Attackers can exploit this flaw by crafting malicious URLs that, when visited by a victim, execute arbitrary JavaScript code. This can lead to unauthorized actions, data theft, or compromise of user accounts.

When exploited, this vulnerability allows attackers to execute scripts in the user's browser, potentially stealing session cookies, redirecting users to malicious websites, or performing unauthorized actions on behalf of the user. The impact depends on the context and privileges of the compromised browser session.

REFERENCES

Solution Advice
  • Update Redirection for Contact Form 7 plugin to version 2.5.0 or later.
  • Review your WordPress installation for any other vulnerable plugins and update them as necessary.
  • Implement a Web Application Firewall (WAF) to monitor and block malicious input.
  • Educate users about the risks of visiting unknown or suspicious URLs.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2022-0250 Scanner - Cross-Site Scripting vulnerability in Redirection for Contact Form 7 S4E