CVE-2024-4704

Contact Form 7 < 5.9.5 - Unauthenticated Open Redirect

The Contact Form 7 WordPress plugin before 5.9.5 has an open redirect that allows an attacker to utilize a false URL and redirect to the URL of their choosing.


We have discovered 1,408,504 live websites that are affected by CVE-2024-4704.

Run a Free Instant Scan




Affected Software

Product  Contact Form 7
Category Form Builders
Vulnerable Domains1,408,504 live websites (39% of Contact Form 7 install base)
Vulnerable Versions
  • from 0 through 5.9.5
Vulnerable Versions Count106 versions ( 83% of all versions)


Common Weakness Enumeration

CWE-601 URL Redirection to Untrusted Site ('Open Redirect')



Details

  • Published - Jun 27, 2024
  • Updated - Aug 1, 2024

Credits

  • William Bastos - cHoR4o (finder)
  • WPScan (coordinator)

Website Distribution by Country

Number of websites using CVE-2024-4704
United States264,883 websites



Japan138,451 websites
Germany137,792 websites
France90,959 websites
Italy81,465 websites
Russia66,244 websites
GB56,059 websites
Poland44,195 websites
Spain44,164 websites
Netherlands43,040 websites

Website Distribution by TLD

Number of websites using CVE-2024-4704
.com539,619 websites
.de76,889 websites
.it56,800 websites
.ru53,639 websites
.org44,044 websites
.nl37,847 websites
.fr37,261 websites
.co.uk36,583 websites
.net35,399 websites
.pl33,415 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-4704

Top websites that are affected by CVE-2024-4704. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
****.br Brazil***
********.com Singapore*,***
************.com United States*,***
*******.org United States*,***
*********.com United States*,***
***************.com United States*,***
*********.com United States*,***
***********.org United States*,***
*****.****.br Brazil*,***
*********.com United States*,***
See full domain list

FAQ

CVE-2024-4704 is URL Redirection to Untrusted Site ('Open Redirect') in Contact Form 7
A total of 1,408,504 websites have been identified as vulnerable to CVE-2024-4704, based on global website indexing conducted by WebTechSurvey.
The Contact Form 7 is affected by the CVE-2024-4704 vulnerability.
Contact Form 7 versions up to 5.9.5 are vulnerable to CVE-2024-4704.
CVE-2024-4704 is resolved in version 5.9.5 of Contact Form 7.