The Contact Form 7 WordPress plugin before 5.9.5 has an open redirect that allows an attacker to utilize a false URL and redirect to the URL of their choosing.
We have discovered 1,408,504 live websites that are affected by CVE-2024-4704.
| Product | |
| Category | Form Builders |
| Vulnerable Domains | 1,408,504 live websites (39% of Contact Form 7 install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 106 versions ( 83% of all versions) |
| 264,883 websites | |
| 138,451 websites | |
| 137,792 websites | |
| 90,959 websites | |
| 81,465 websites | |
| 66,244 websites | |
| 56,059 websites | |
| 44,195 websites | |
| 44,164 websites | |
| 43,040 websites |
| .com | 539,619 websites |
| .de | 76,889 websites |
| .it | 56,800 websites |
| .ru | 53,639 websites |
| .org | 44,044 websites |
| .nl | 37,847 websites |
| .fr | 37,261 websites |
| .co.uk | 36,583 websites |
| .net | 35,399 websites |
| .pl | 33,415 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ****.br | *** | ||
| ********.com | *,*** | ||
| ************.com | *,*** | ||
| *******.org | *,*** | ||
| *********.com | *,*** | ||
| ***************.com | *,*** | ||
| *********.com | *,*** | ||
| ***********.org | *,*** | ||
| *****.****.br | *,*** | ||
| *********.com | *,*** |
FAQ