CVE-2024-4704: Rocklobster Contact Form 7

Medium severity, CVSS 6.1. EPSS: 0.4% chance of exploitation in the next 30 days.

The Contact Form 7 WordPress plugin before 5.9.5 has an open redirect that allows an attacker to utilize a false URL and redirect to the URL of their choosing.

Affected products

  • Rocklobster Contact Form 7: before 5.9.5 (fixed in 5.9.5)

Published 2024-06-27. Last modified 2026-06-17.