Querysol maintains a narrowly focused product portfolio centered on WordPress plugins, with a documented vulnerability pattern concentrated in its Redirection for Contact Form 7 extension. The recurring weakness classes affecting this vendor involve incorrect authorization and deserialization of untrusted data, reflecting the trust-boundary and input-handling requirements of WordPress plugin architecture. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Querysol over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-24278HIGH In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, unauthenticated users can use the wpcf7r_get_nonce AJAX action to retrieve a valid nonce for any WordPress acti | May 14, 2021 | 7.5 | 35 | NO | YES |
CVE-2021-24280HIGH In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, any authenticated user, such as a subscriber, could use the import_from_debug AJAX action to inject PHP objects | May 14, 2021 | 8.8 | 26 | NO | NO |
CVE-2021-24282MEDIUM In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, any authenticated user, such as a subscriber, could use the various AJAX actions in the plugin to do a variety | May 14, 2021 | 6.3 | 20 | NO | NO |
CVE-2021-24279MEDIUM In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, low level users, such as subscribers, could use the import_from_debug AJAX action to install any plugin from th | May 14, 2021 | 6.5 | 20 | NO | NO |
CVE-2021-24281MEDIUM In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, any authenticated user, such as a subscriber, could use the delete_action_post AJAX action to delete any post o | May 14, 2021 | 4.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Querysol.
Media articles that mention a CVE ID that affects a product developed by Querysol — matched by CVE ID, not by vendor name.