CVE-2023-23990 HIGH

CVE-2023-23990: WordPress Redirection for Contact Form 7 plugin <= 2.7.0 - Privilege Escalation vulnerability

Vendor Qube One Ltd.
Product Redirection for Contact Form 7
Weakness CWE-269
Published May 17, 2024
Last update April 28, 2026

CVSS base score

7.6/10
Attack vector Network
Attack complexity High
Privileges required High
User interaction Required
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H

What the vulnerability does

01Description

Improper Privilege Management vulnerability in Qube One Ltd. Redirection for Contact Form 7 wpcf7-redirect allows Privilege Escalation.This issue affects Redirection for Contact Form 7: from n/a through 2.7.0.

Explanation of Vulnerability in Simple Terms

02Summary

Redirection for Contact Form 7 through version 2.7.0 contains a privilege management flaw that allows high-privileged users to perform unauthorized actions when a victim visits a malicious page. The vulnerability requires administrator-level access and user interaction to exploit, but can result in full compromise of site data and functionality when successful.

What an attacker can do

03Attacker Capabilities

An admin user can trick another admin into visiting a malicious page to read, modify, or delete site data.

Potential impact on your site

04Site Impact

An administrator's account could be abused to alter or delete site content, user data, or plugin settings without their knowledge.

Conditions required to exploit

05Prerequisites

Attacker must have administrator access; victim admin must click a malicious link or visit an attacker-controlled page.

Key dates

06Disclosure timeline

May 17, 2024 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE