
Redirection for Contact Form 7 Security & Risk Analysis
wordpress.org/plugins/wpcf7-redirectRedirect to any page or URL, execute scripts after submission, save data to the database, and unlock additional submission actions for Contact Form 7.
Is Redirection for Contact Form 7 Safe to Use in 2026?
Generally Safe
Score 88/100Redirection for Contact Form 7 has a strong security track record. Known vulnerabilities have been patched promptly.
The wpcf7-redirect plugin v3.2.9 presents a mixed security posture. While it demonstrates good practices such as using prepared statements for all SQL queries and a high percentage of properly escaped output, significant concerns arise from its attack surface and past vulnerability history. A substantial portion of its AJAX handlers (7 out of 7) lack authentication checks, creating a broad entry point for potential attacks. Additionally, the taint analysis reveals two high-severity flows, indicating potential for malicious data to be processed without adequate sanitization.
The plugin's historical vulnerability record is a major red flag. With 14 known CVEs, including a significant number of high and medium severity issues, and a recent vulnerability reported in late 2025, this plugin has a consistent track record of security flaws. The common vulnerability types like 'Deserialization of Untrusted Data,' 'Missing Authorization,' and 'Improper Neutralization of Input During Web Page Generation' are particularly worrying and align with the concerns identified in the static analysis. The presence of the `unserialize` function, without explicit context on its usage, in conjunction with high-severity taint flows and historical deserialization vulnerabilities, is a critical risk.
In conclusion, despite some positive coding practices, the plugin's large number of unprotected AJAX endpoints, critical taint analysis findings, and extensive history of high-severity vulnerabilities suggest a high overall risk. While there are no currently unpatched CVEs, the plugin's past performance and the identified weaknesses in the current version necessitate caution and vigilance.
Key Concerns
- AJAX handlers without authentication checks
- High severity taint flows
- Unsafe unserialize function detected
- History of high severity CVEs
- History of medium severity CVEs
- Deserialization of Untrusted Data vulnerability history
- Missing Authorization vulnerability history
- Cross-site Scripting vulnerability history
- Path Traversal vulnerability history
Redirection for Contact Form 7 Security Vulnerabilities
CVEs by Year
Severity Breakdown
14 total CVEs
Redirection for Contact Form 7 <= 3.2.7 - Unauthenticated Arbitrary File Copy via move_file_to_upload
Redirection for Contact Form 7 <= 3.2.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via qs_date Shortcode
Redirection for Contact Form 7 <= 3.2.4 - Unauthenticated Arbitrary File Deletion
Redirection for Contact Form 7 <= 3.2.4 - Unauthenticated PHP Object Injection via PHAR Deserialization
Redirection for Contact Form 7 <= 3.2.4 - Unauthenticated PHP Object Injection
Redirection for Contact Form 7 <= 2.9.2 - Missing Authorization
Redirection for Contact Form 7 <= 2.7.0 - Authenticated(Editor+) Privilege Escalation
Redirection for Contact Form 7 <= 2.4.0 - Missing Authorization
Redirection for Contact Form 7 <= 2.4.0 - Reflected Cross-Site Scripting
Redirection for Contact Form 7 <= 2.3.3 - Authenticated Arbitrary Plugin Installation
Redirection for Contact Form 7 <= 2.3.3 - Unauthenticated Arbitrary Nonce Generation
Redirection for Contact Form 7 <= 2.3.3 - Authenticated PHP Object Injection
Redirection for Contact Form 7 <= 2.3.3 - Unprotected AJAX Actions
Redirection for Contact Form 7 <= 2.3.3 - Authenticated Arbitrary Post Deletion
Redirection for Contact Form 7 Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Redirection for Contact Form 7 Attack Surface
AJAX Handlers 7
REST API Routes 2
Shortcodes 3
WordPress Hooks 84
Maintenance & Trust
Redirection for Contact Form 7 Maintenance & Trust
Maintenance Signals
Community Trust
Redirection for Contact Form 7 Alternatives
Page Redirection For CF7
cf7-thank-you-page
Page Redirection For CF7 helps you to redirect on thank you page after the contact form is submitted successfully.
Connect Contact Form 7 and Mailchimp
contact-form-7-mailchimp-extension
Connect Contact Form 7 to Mailchimp. Automatically sync form submissions to your Mailchimp audiences with merge field mapping, double opt-in, and opt- …
Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms
cf7-mailchimp
Send Contact Form 7, WPforms, Elementor, Ninja Forms, CRM Perks Forms and many other contact form submissions to Mailchimp.
Accept PayPal Payments using Contact Form 7
contact-form-7-paypal-extension
Integrate PayPal Submit button in Contact Form 7 to Enjoy Quick Online Payments.
wpSUBpages Redirect
redirect-page
redirect to page does, what the name says and a little bit more. it redirects pages to pages, subpages and external uris.
Redirection for Contact Form 7 Developer Profile
37 plugins · 2.2M total installs
How We Detect Redirection for Contact Form 7
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wpcf7-redirect/assets/js/wpcf7r-pro-redirect.js/wp-content/plugins/wpcf7-redirect/assets/css/wpcf7r-pro-redirect.css/wp-content/plugins/wpcf7-redirect/assets/js/wpcf7r-pro-redirect.jswpcf7-redirect/assets/js/wpcf7r-pro-redirect.js?ver=wpcf7-redirect/assets/css/wpcf7r-pro-redirect.css?ver=HTML / DOM Fingerprints
wpcf7r-pro-redirectdata-wpcf7r-pro-redirectwpcf7r_pro_redirect_object