CVE-2021-36913 is an unauthenticated Options Change and Content Injection vulnerability affecting the Qube One Redirection for Contact Form 7 plugin up to version 2.4.0 for WordPress, specifically when the AccessiBe extension is also installed. This high-severity vulnerability (CVSS 7.5) allows attackers to modify plugin options and inject scripts into the website's footer HTML without authentication, leading to potential website defacement or cross-site scripting. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.6.0CPE matchmatch criteria | cpe:2.3:a:redirection-for-contact-form7:redirection_for_contact_form_7:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.