SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-80439

MEDIUM · CVSS 4.8 EPSS 0.23%

Source: NVD + CISA KEV + EPSS · Published 2026-09-06 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The Redirection for Contact Form 7 WordPress plugin versions prior to 3.2.11 are vulnerable to unauthorized shortcode execution, enabling unauthenticated users to manipulate form submissions and access potentially sensitive output. This vulnerability poses a medium risk, as it could lead to information disclosure or further exploitation of the site. WordPress site administrators using affected versions should prioritize updating the plugin to mitigate this risk.

CVE
CVE-2026-80439
Severity
MEDIUM
CVSS
4.8
EPSS
0.23%
WordPress

Original NVD Description

The Redirection for Contact Form 7 WordPress plugin from 2.2.7 before 3.2.11 does not prevent shortcodes in submitted form values from being executed when it substitutes those values into an action's settings and then processes those settings for shortcodes, allowing unauthenticated users to run any shortcode registered on the site and read its output.