{"error":0,"message":null,"data":{"name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You","plugin":"ninja-forms","link":"https:\/\/wordpress.org\/plugins\/ninja-forms\/","latest":"1788796800","closed":0,"closed_reason":null,"closed_date":null,"vulnerability":[{"uuid":"f5104a70b4161d3391f364214c0e32ad471e822280d7922d59c24cd4ba868b0e","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.6.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.6.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2021-24889","name":"CVE-2021-24889","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2021-24889","description":"[en] The Ninja Forms Contact Form WordPress plugin before 3.6.4 does not escape keys of the fields POST parameter, which could allow high privilege users to perform SQL injections attacks","date":"2021-11-29"},{"id":"a692442a79a11d38ab14176f021255ff0c017dd5","name":"WordPress Ninja Forms Contact Form plugin <= 3.6.3 - SQL Injection (SQLi) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ninja-forms\/vulnerability\/wordpress-ninja-forms-contact-form-plugin-3-6-3-sql-injection-sqli-vulnerability","description":"SQL Injection (SQLi) vulnerability discovered by JrXnm in WordPress Ninja Forms Contact Form plugin (versions <= 3.6.3).","date":"2021-10-26"},{"id":"51e66dddbf6bf4d65ec486047820d92f03105fea","name":"Ninja Forms Contact Form <= 3.6.3 - Authenticated SQL Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ninja-forms\/ninja-forms-contact-form-363-authenticated-sql-injection","description":"The Ninja Forms Contact Form WordPress plugin before 3.6.4 does not escape keys of the fields POST parameter, which could allow high privilege users to perform SQL injections attacks","date":"2021-10-26"},{"id":"55008a42-eb56-436c-bce0-10ee616d0495","name":"Ninja Forms &lt; 3.6.4 - Admin+ SQL Injection","link":"https:\/\/wpscan.com\/vulnerability\/55008a42-eb56-436c-bce0-10ee616d0495","description":"The plugin does not escape keys of the fields POST parameter, which could allow high privilege users to perform SQL injections attacks","date":null},{"id":"EUVD-2021-11801","name":"EUVD-2021-11801","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2021-11801","description":"The Ninja Forms Contact Form WordPress plugin before 3.6.4 does not escape keys of the fields POST parameter, which could allow high privilege users to perform SQL injections attacks","date":"2021-11-30"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"h","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"7.2","severity":"h","exploitable":"1.2","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"7.2","severity":"high","av":"network","ac":"low","pr":"high","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"1.2","impact":"5.9"},"cwe":[{"cwe":"CWE-89","name":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')","description":"The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data."}],"epss":"0.006"}},{"uuid":"8b0acc4ecd463ad4465937752558f88d51adbb77bde47e17e1c4df08b569b24d","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.6.8","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.6.8","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2021-24381","name":"CVE-2021-24381","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2021-24381","description":"[en] The Ninja Forms Contact Form WordPress plugin before 3.5.8.2 does not sanitise and escape the custom class name of the form field created, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.","date":"2021-10-25"},{"id":"3423735172344d58cb6e7639299de70e58998e43","name":"WordPress Ninja Forms Contact Form plugin <= 3.5.8.1 - Stored Cross-Site Scripting (XSS) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ninja-forms\/vulnerability\/wordpress-ninja-forms-contact-form-plugin-3-5-8-1-stored-cross-site-scripting-xss-vulnerability","description":"Stored Cross-Site Scripting (XSS) vulnerability discovered by Rodel Plasabas in WordPress Ninja Forms Contact Form plugin (versions <= 3.5.8.1).","date":"2021-09-27"},{"id":"195a29d3342d49d3674708750e0cf19a0bbd61e2","name":"Ninja Forms <= 3.5.8.1 - Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ninja-forms\/ninja-forms-3581-cross-site-scripting","description":"The Ninja Forms Contact Form WordPress plugin before 3.5.8.2 does not sanitise and escape the custom class name of the form field created, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.","date":"2021-09-27"},{"id":"e383fae6-e0da-4aba-bb62-adf51c01bf8d","name":"NinjaForms &lt; 3.5.8.2 - Admin+ Stored Cross-Site Scripting","link":"https:\/\/wpscan.com\/vulnerability\/e383fae6-e0da-4aba-bb62-adf51c01bf8d","description":"The plugin does not sanitise and escape the custom class name of the form field created, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"h","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"4.8","severity":"m","exploitable":"1.7","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"4.8","severity":"medium","av":"network","ac":"low","pr":"high","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"1.7","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"9f7b08ed4e4c19574bdb55b429410e4c28dd93ae27d2dee5dd6b265541911154","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.5.8","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.5.8","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2021-34647","name":"CVE-2021-34647","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2021-34647","description":"[en] The Ninja Forms WordPress plugin is vulnerable to sensitive information disclosure via the bulk_export_submissions function found in the ~\/includes\/Routes\/Submissions.php file, in versions up to and including 3.5.7. This allows authenticated attackers to export all Ninja Forms submissions data via the \/ninja-forms-submissions\/export REST API which can include personally identifiable information.","date":"2021-09-22"},{"id":"4a974b16b4af053c84d8f9c0472310d5c51cffe1","name":"WordPress Ninja Forms Contact Form plugin <= 3.5.7 - Unprotected REST-API to Sensitive Information Disclosure vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ninja-forms\/vulnerability\/wordpress-ninja-forms-contact-form-plugin-3-5-7-unprotected-rest-api-to-sensitive-information-disclosure-vulnerability","description":"Unprotected REST-API to Sensitive Information Disclosure vulnerability discovered by Chloe Chamberland (WordFence) in WordPress Ninja Forms Contact Form plugin (versions <= 3.5.7).","date":"2021-09-22"},{"id":"de192b8226aaae293369086d125d07a2213edfa8","name":"Ninja Forms <= 3.5.7 - Unprotected REST-API to Sensitive Information Disclosure","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ninja-forms\/ninja-forms-357-unprotected-rest-api-to-sensitive-information-disclosure","description":"The Ninja Forms WordPress plugin is vulnerable to sensitive information disclosure via the bulk_export_submissions function found in the ~\/includes\/Routes\/Submissions.php file, in versions up to and including 3.5.7. This allows authenticated attackers to export all Ninja Forms submissions data via the \/ninja-forms-submissions\/export REST API which can include personally identifiable information.","date":"2021-09-22"},{"id":"606973aa-cf5d-43a7-9ef5-faa7f9af5318","name":"Ninja Forms &lt; 3.5.8 - Unprotected REST-API to Sensitive Information Disclosure","link":"https:\/\/wpscan.com\/vulnerability\/606973aa-cf5d-43a7-9ef5-faa7f9af5318","description":"The plugin is vulnerable to sensitive information disclosure via the bulk_export_submissions function found in the ~\/includes\/Routes\/Submissions.php file, in versions up to and including 3.5.7. This allows authenticated attackers to export all Ninja Forms submissions data via the \/ninja-forms-submissions\/export REST API which can include personally identifiable information.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:N\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"h","i":"n","a":"n","score":"6.5","severity":"m","exploitable":"2.8","impact":"3.6"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:N\/A:N","score":"6.5","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"high","i":"none","a":"none","exploitable":"2.8","impact":"3.6"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."},{"cwe":"CWE-863","name":"Incorrect Authorization","description":"The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"53a3e748fb2266218252dbe830f72aef46e500951da05ff2dd92caafcc9b4039","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.5.8","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.5.8","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2021-34648","name":"CVE-2021-34648","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2021-34648","description":"[en] The Ninja Forms WordPress plugin is vulnerable to arbitrary email sending via the trigger_email_action function found in the ~\/includes\/Routes\/Submissions.php file, in versions up to and including 3.5.7. This allows authenticated attackers to send arbitrary emails from the affected server via the \/ninja-forms-submissions\/email-action REST API which can be used to socially engineer victims.","date":"2021-09-22"},{"id":"edf924ed61faa9e590de23c6dba4acaffd4db374","name":"WordPress Ninja Forms Contact Form plugin <= 3.5.7 - Unprotected REST-API to Email Injection vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ninja-forms\/vulnerability\/wordpress-ninja-forms-contact-form-plugin-3-5-7-unprotected-rest-api-to-email-injection-vulnerability","description":"Unprotected REST-API to Email Injection vulnerability discovered by Chloe Chamberland (WordFence) in WordPress Ninja Forms Contact Form plugin (versions <= 3.5.7).","date":"2021-09-22"},{"id":"a575caae9b7a53cc16bbb09373812e3f6d8fbd76","name":"Ninja Forms <= 3.5.7 - Unprotected REST-API to Email Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ninja-forms\/ninja-forms-357-unprotected-rest-api-to-email-injection","description":"The Ninja Forms WordPress plugin is vulnerable to arbitrary email sending via the trigger_email_action function found in the ~\/includes\/Routes\/Submissions.php file, in versions up to and including 3.5.7. This allows authenticated attackers to send arbitrary emails from the affected server via the \/ninja-forms-submissions\/email-action REST API which can be used to socially engineer victims.","date":"2021-09-22"},{"id":"b9f6dad5-2293-482f-9ee6-dc8b4c713b80","name":"Ninja Forms &lt; 3.5.8 - Unprotected REST-API to Email Injection","link":"https:\/\/wpscan.com\/vulnerability\/b9f6dad5-2293-482f-9ee6-dc8b4c713b80","description":"The plugin is vulnerable to arbitrary email sending via the trigger_email_action function found in the ~\/includes\/Routes\/Submissions.php file, in versions up to and including 3.5.7. This allows authenticated attackers to send arbitrary emails from the affected server via the \/ninja-forms-submissions\/email-action REST API which can be used to socially engineer victims.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"n","i":"l","a":"n","score":"4.3","severity":"m","exploitable":"2.8","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:L\/A:N","score":"4.3","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"none","i":"low","a":"none","exploitable":"2.8","impact":"1.4"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."},{"cwe":"CWE-863","name":"Incorrect Authorization","description":"The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"d6d1a22e238df9e275702055b47ff7acc578eda53b05d346e12b65c1b2bcc2cb","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.4.34","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.4.34","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2021-24165","name":"CVE-2021-24165","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2021-24165","description":"[en] In the Ninja Forms Contact Form WordPress plugin before 3.4.34, the wp_ajax_nf_oauth_connect AJAX action was vulnerable to open redirect due to the use of a user supplied redirect parameter and no protection in place.","date":"2021-04-05"},{"id":"21909186be3c6c54e5f2ee5571afa48e56d21dba","name":"Ninja Forms Contact Form <= 3.4.33 - Administrator Open Redirect","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ninja-forms\/ninja-forms-contact-form-3433-administrator-open-redirect","description":"In the Ninja Forms Contact Form WordPress plugin before 3.4.34, the wp_ajax_nf_oauth_connect AJAX action was vulnerable to open redirect due to the use of a user supplied redirect parameter and no protection in place.","date":"2021-02-16"},{"id":"6147acf5-e43f-47e6-ab56-c9c8be584818","name":"Ninja Forms &lt; 3.4.34 - Administrator Open Redirect","link":"https:\/\/wpscan.com\/vulnerability\/6147acf5-e43f-47e6-ab56-c9c8be584818","description":"The wp_ajax_nf_oauth_connect AJAX action was vulnerable to open redirect due to the use of a user supplied redirect parameter and no protection in place.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-601","name":"URL Redirection to Untrusted Site ('Open Redirect')","description":"The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect."}]}},{"uuid":"b62f57be8bb268ad823413ec44a4d14006072987c24d5ad5f4371d1aa51f2977","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.4.34","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.4.34","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2021-24163","name":"CVE-2021-24163","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2021-24163","description":"[en] The AJAX action, wp_ajax_ninja_forms_sendwp_remote_install_handler, did not have a capability check on it, nor did it have any nonce protection, therefore making it possible for low-level users, such as subscribers, to install and activate the SendWP Ninja Forms Contact Form \u2013 The Drag and Drop Form Builder for WordPress WordPress plugin before 3.4.34 and retrieve the client_secret key needed to establish the SendWP connection while also installing the SendWP plugin.","date":"2021-04-05"},{"id":"5d48ad009df049069da11592900539795baeacf2","name":"Ninja Forms Contact Form <= 3.4.33 - Authenticated SendWP Plugin Installation and Client Secret Key Disclosure","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ninja-forms\/ninja-forms-contact-form-3433-authenticated-sendwp-plugin-installation-and-client-secret-key-disclosure","description":"The AJAX action, wp_ajax_ninja_forms_sendwp_remote_install_handler, did not have a capability check on it, nor did it have any nonce protection, therefore making it possible for low-level users, such as subscribers, to install and activate the SendWP Ninja Forms Contact Form \u2013 The Drag and Drop Form Builder for WordPress WordPress plugin before 3.4.34 and retrieve the client_secret key needed to establish the SendWP connection while also installing the SendWP plugin.","date":"2021-02-16"},{"id":"55fde9fa-f6cd-4546-bee8-4acc628251c2","name":"Ninja Forms &lt; 3.4.34 - Authenticated SendWP Plugin Installation and Client Secret Key Disclosure","link":"https:\/\/wpscan.com\/vulnerability\/55fde9fa-f6cd-4546-bee8-4acc628251c2","description":"The AJAX action, wp_ajax_ninja_forms_sendwp_remote_install_handler, did not have a capability check on it, nor did it have any nonce protection, therefore making it possible for low-level users, such as subscribers, to install and activate the SendWP plugin and retrieve the client_secret key needed to establish the SendWP connection while also installing the SendWP plugin.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"8.8","severity":"h","exploitable":"2.8","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"8.8","severity":"high","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"2.8","impact":"5.9"},"cwe":[{"cwe":"CWE-200","name":"Exposure of Sensitive Information to an Unauthorized Actor","description":"The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information."},{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}]}},{"uuid":"a86ae29e86f909fce824128d66e9cb2a245a486ff3ce6f2ec3b9ce87b1855e50","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.4.34.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.4.34.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2021-24164","name":"CVE-2021-24164","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2021-24164","description":"[en] In the Ninja Forms Contact Form WordPress plugin before 3.4.34.1, low-level users, such as subscribers, were able to trigger the action, wp_ajax_nf_oauth, and retrieve the connection url needed to establish a connection. They could also retrieve the client_id for an already established OAuth connection.","date":"2021-04-05"},{"id":"45c6781767c16574cc36e3582df48a8bbb60f3d0","name":"Ninja Forms <= 3.4.34 - Authenticated OAuth Connection Key Disclosure","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ninja-forms\/ninja-forms-3434-authenticated-oauth-connection-key-disclosure","description":"In the Ninja Forms Contact Form WordPress plugin before 3.4.34.1, low-level users, such as subscribers, were able to trigger the action, wp_ajax_nf_oauth, and retrieve the connection url needed to establish a connection. They could also retrieve the client_id for an already established OAuth connection.","date":"2021-02-16"},{"id":"dfa32afa-c6de-4237-a9f2-709843dcda89","name":"Ninja Forms &lt; 3.4.34.1 - Authenticated OAuth Connection Key Disclosure","link":"https:\/\/wpscan.com\/vulnerability\/dfa32afa-c6de-4237-a9f2-709843dcda89","description":"Low-level users, such as subscribers, were able to trigger the action, wp_ajax_nf_oauth, and retrieve the connection url needed to establish a connection. They could also retrieve the client_id for an already established OAuth connection.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:L\/I:N\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"l","i":"n","a":"n","score":"4.3","severity":"m","exploitable":"2.8","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:L\/I:N\/A:N","score":"4.3","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"low","i":"none","a":"none","exploitable":"2.8","impact":"1.4"},"cwe":[{"cwe":"CWE-200","name":"Exposure of Sensitive Information to an Unauthorized Actor","description":"The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information."},{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}]}},{"uuid":"6154778fec6cd05cf74e658ebfda07838a2fbf20a704f5bae664097ea68f134f","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.4.34","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.4.34","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2021-24166","name":"CVE-2021-24166","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2021-24166","description":"[en] The wp_ajax_nf_oauth_disconnect from the Ninja Forms Contact Form \u2013 The Drag and Drop Form Builder for WordPress WordPress plugin before 3.4.34 had no nonce protection making it possible for attackers to craft a request to disconnect a site's OAuth connection.","date":"2021-04-05"},{"id":"b2c24ae05c3c6df8e6ccbfdb981aae5bf757ae50","name":"Ninja Forms Contact Form <= 3.4.33 - Cross-Site Request Forgery to OAuth Service Disconnection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ninja-forms\/ninja-forms-contact-form-3433-cross-site-request-forgery-to-oauth-service-disconnection","description":"The wp_ajax_nf_oauth_disconnect from the Ninja Forms Contact Form \u2013 The Drag and Drop Form Builder for WordPress WordPress plugin before 3.4.34 had no nonce protection making it possible for attackers to craft a request to disconnect a site's OAuth connection.","date":"2021-02-16"},{"id":"b531fb65-a8ff-4150-a9a1-2a62a3c00bd6","name":"Ninja Forms &lt; 3.4.34 - CSRF to OAuth Service Disconnection","link":"https:\/\/wpscan.com\/vulnerability\/b531fb65-a8ff-4150-a9a1-2a62a3c00bd6","description":"The wp_ajax_nf_oauth_disconnect from the plugin had no nonce protection making it possible for attackers to craft a request to disconnect a site&#039;s OAuth connection.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:L\/A:L","av":"n","ac":"l","pr":"n","ui":"r","s":"u","c":"n","i":"l","a":"l","score":"5.4","severity":"m","exploitable":"2.8","impact":"2.5"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:L\/A:L","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"unchanged","c":"none","i":"low","a":"low","exploitable":"2.8","impact":"2.5"},"cwe":[{"cwe":"CWE-352","name":"Cross-Site Request Forgery (CSRF)","description":"The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor."}]}},{"uuid":"d53bb4a1e69f32b0196f552c7bdea824eeb594c572ca39dfb63b31d1a590e7a8","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.4.28","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.4.28","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2020-36173","name":"CVE-2020-36173","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2020-36173","description":"[en] The Ninja Forms plugin before 3.4.28 for WordPress lacks escaping for submissions-table fields.","date":"2021-01-06"},{"id":"c99d87dd45bb0da60a0638ccedfa20214227b63d","name":"Ninja Forms Contact Form \u2013 The Drag and Drop Form Builder for WordPress <= 3.4.27.1 - Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ninja-forms\/ninja-forms-contact-form-the-drag-and-drop-form-builder-for-wordpress-34271-stored-cross-site-scripting","description":"The Ninja Forms plugin before 3.4.28 for WordPress lacks escaping for submissions-table fields.","date":"2020-09-20"},{"id":"4b4e5cf0-1c18-450b-b36d-848f8b958e34","name":"Ninja Forms &lt; 3.4.28 - Stored Cross-Site Scripting","link":"https:\/\/wpscan.com\/vulnerability\/4b4e5cf0-1c18-450b-b36d-848f8b958e34","description":"The plugin did not escape HTML content of fields in the submissions table, which could lead to Cross-Site Scripting issues","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"n","i":"l","a":"n","score":"5.3","severity":"m","exploitable":"3.9","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:L\/A:N","score":"5.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"none","i":"low","a":"none","exploitable":"3.9","impact":"1.4"},"cwe":[{"cwe":"CWE-116","name":"Improper Encoding or Escaping of Output","description":"The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved."}]}},{"uuid":"918cc7248ace5dbd6ceabcab42badbd8ad4cefb000be6d28022a7d82c88a5882","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.4.27.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.4.27.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2020-36174","name":"CVE-2020-36174","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2020-36174","description":"[en] The Ninja Forms plugin before 3.4.27.1 for WordPress allows CSRF via services integration.","date":"2021-01-06"},{"id":"a3bc975f40a19a7048fda47d072eea38a3fdbfd3","name":"Ninja Forms Contact Form \u2013 The Drag and Drop Form Builder for WordPress <= 3.4.27 - Cross-Site Request Forgery to Plugin Installation","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ninja-forms\/ninja-forms-contact-form-the-drag-and-drop-form-builder-for-wordpress-3427-cross-site-request-forgery-to-plugin-installation","description":"The Ninja Forms plugin before 3.4.27.1 for WordPress allows CSRF via services integration. This makes it possible for attackers to install arbitrary plugins.","date":"2020-09-22"},{"id":"eb25a43e-0db9-4aa5-aad9-319a7b620da4","name":"Ninja Forms &lt; 3.4.27.1 - CSRF leading to Arbitrary Plugin Installation","link":"https:\/\/wpscan.com\/vulnerability\/eb25a43e-0db9-4aa5-aad9-319a7b620da4","description":"The plugin is affected by a Cross-Site Request Forgery (CSRF) which could allow attackers to make a logged administrator install an arbitrary plugin from the WordPress repository.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:H\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"u","c":"n","i":"h","a":"n","score":"6.5","severity":"m","exploitable":"2.8","impact":"3.6"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:H\/A:N","score":"6.5","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"unchanged","c":"none","i":"high","a":"none","exploitable":"2.8","impact":"3.6"},"cwe":[{"cwe":"CWE-352","name":"Cross-Site Request Forgery (CSRF)","description":"The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor."}]}},{"uuid":"aa06ea47e5b6cb034358dd1da9921f6c4e3b5c2463e55e4e30cb6d342ce5c8e9","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.4.27.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.4.27.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2020-36175","name":"CVE-2020-36175","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2020-36175","description":"[en] The Ninja Forms plugin before 3.4.27.1 for WordPress allows attackers to bypass validation via the email field.","date":"2021-01-06"},{"id":"2c0206af1e740eab41385eba7c891002c0e36311","name":"Ninja Forms Contact Form \u2013 The Drag and Drop Form Builder for WordPress <= 3.4.27 - Validation Bypass via Email Field","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ninja-forms\/ninja-forms-contact-form-the-drag-and-drop-form-builder-for-wordpress-3427-validation-bypass-via-email-field","description":"The Ninja Forms plugin before 3.4.27.1 for WordPress allows attackers to bypass validation via the email field.","date":"2020-09-22"},{"id":"3311c312-41b0-4004-a1e1-84ad3f46f094","name":"Ninja Forms &lt; 3.4.27.1 - Validation Bypass via Email Field","link":"https:\/\/wpscan.com\/vulnerability\/3311c312-41b0-4004-a1e1-84ad3f46f094","description":"The plugin did not correctly validate the email address field.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"n","i":"l","a":"n","score":"5.3","severity":"m","exploitable":"3.9","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:L\/A:N","score":"5.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"none","i":"low","a":"none","exploitable":"3.9","impact":"1.4"},"cwe":[{"cwe":"CWE-20","name":"Improper Input Validation","description":"The product receives input or data, but it does\n        not validate or incorrectly validates that the input has the\n        properties that are required to process the data safely and\n        correctly."}]}},{"uuid":"2c8266abd86efb4f2e6742d3bfa2815ea905f7651631286236e21e93eee61d8a","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.4.24.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.4.24.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2020-12462","name":"CVE-2020-12462","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2020-12462","description":"[en] The ninja-forms plugin before 3.4.24.2 for WordPress allows CSRF with resultant XSS.","date":"2020-04-29"},{"id":"e47268d05006143cd7aff2fa8072338ce42c31b8","name":"Ninja Forms Contact Form <= 3.4.24.1 - Cross-Site Request Forgery leading to Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ninja-forms\/ninja-forms-contact-form-34241-cross-site-request-forgery-leading-to-stored-cross-site-scripting","description":"The Ninja Forms plugin before 3.4.24.2 for WordPress allows CSRF with resultant XSS.","date":"2020-04-28"},{"id":"3d15050c-cd43-4fe0-bf89-4ccfc170d23a","name":"Ninja Forms &lt; 3.4.24.2 - CSRF to Stored XSS","link":"https:\/\/wpscan.com\/vulnerability\/3d15050c-cd43-4fe0-bf89-4ccfc170d23a","description":"Ramuel Gall of Wordfence discovered a Cross-Site Request Forgery(CSRF) plugin vulnerability within the Ninja Forms WordPress plugin. By exploiting the CSRF vulnerability, an attacker could inject arbitrary malicious JavaScript via the import contact feature.\r\n\r\nThis vulnerability was reportedly fixed in version 3.4.24.2.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-352","name":"Cross-Site Request Forgery (CSRF)","description":"The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor."}]}},{"uuid":"1957cd85111b629a89291e86a58cfa609295c6e647d00944b5f5fe61ef3d52c7","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.4.23","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.4.23","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2020-8594","name":"CVE-2020-8594","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2020-8594","description":"[en] The Ninja Forms plugin 3.4.22 for WordPress has Multiple Stored XSS vulnerabilities via ninja_forms[recaptcha_site_key], ninja_forms[recaptcha_secret_key], ninja_forms[recaptcha_lang], or ninja_forms[date_format].","date":"2020-02-14"},{"id":"7f1bf22665607f32b2162a93b4f08a6979fd152d","name":"Ninja Forms Contact Form <= 3.4.22 - Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ninja-forms\/ninja-forms-contact-form-3422-stored-cross-site-scripting","description":"The Ninja Forms plugin 3.4.22 for WordPress has Multiple Stored XSS vulnerabilities via ninja_forms[recaptcha_site_key], ninja_forms[recaptcha_secret_key], ninja_forms[recaptcha_lang], or ninja_forms[date_format].","date":"2020-02-03"},{"id":"33803764-c473-4055-8def-c5b0647aade9","name":"Ninja Forms &lt; 3.4.23 - CSRF to Stored Cross-Site Scripting (XSS)","link":"https:\/\/wpscan.com\/vulnerability\/33803764-c473-4055-8def-c5b0647aade9","description":"Authenticated Stored XSS vulnerabilities in recaptcha_site_key, recaptcha_secret_key, recaptcha_lang and date_format keys, which can be performed via CSRF attacks.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"b851e90f35d407c3a08bac5348ef033689255b663a0eb494ad0603a29313ece3","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.3.9","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.3.9","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2018-20981","name":"CVE-2018-20981","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2018-20981","description":"[en] The ninja-forms plugin before 3.3.9 for WordPress has insufficient restrictions on submission-data retrieval during Export Personal Data requests.","date":"2019-08-22"},{"id":"ba2bdf2ab0f752025c219bf1911824fc519e92c8","name":"Ninja Forms <= 3.3.8 - Insufficient Restrictions during Export Personal Data requests","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ninja-forms\/ninja-forms-338-insufficient-restrictions-during-export-personal-data-requests","description":"The ninja-forms plugin before 3.3.9 for WordPress has insufficient restrictions on submission-data retrieval during Export Personal Data requests.","date":"2018-07-06"},{"id":"75e94164-b1cc-4313-9279-32fe3e0febc0","name":"Ninja Forms &lt; 3.3.9 - Insufficient Restrictions during Export Personal Data requests","link":"https:\/\/wpscan.com\/vulnerability\/75e94164-b1cc-4313-9279-32fe3e0febc0","description":"The Ninja Forms Contact Form &ndash; The Drag and Drop Form Builder for WordPress WordPress plugin was affected by an Insufficient Restrictions during Export Personal Data requests security vulnerability.","date":null}],"impact":{"cvss":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"h","i":"h","a":"n","score":"9.1","severity":"c","exploitable":"3.9","impact":"5.2"},"cvss3":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:N","score":"9.1","severity":"critical","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"high","i":"high","a":"none","exploitable":"3.9","impact":"5.2"},"cwe":[{"cwe":"CWE-20","name":"Improper Input Validation","description":"The product receives input or data, but it does\n        not validate or incorrectly validates that the input has the\n        properties that are required to process the data safely and\n        correctly."}]}},{"uuid":"c4b7a04e500ceeb3a8b719d9c8d23de13d999671870e912647927ea45517e50f","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.2.15","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.2.15","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2018-20980","name":"CVE-2018-20980","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2018-20980","description":"[en] The ninja-forms plugin before 3.2.15 for WordPress has parameter tampering.","date":"2019-08-22"},{"id":"3a9fbd6116c56451ff720015fa7882cfc65248fb","name":"Ninja Forms Contact Form <= 3.2.14 - Parameter Tampering","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ninja-forms\/ninja-forms-contact-form-3214-parameter-tampering","description":"The ninja-forms plugin before 3.2.15 for WordPress has parameter tampering.","date":"2018-02-26"},{"id":"8c4f0824-6f50-4804-88ed-72617b2e339b","name":"Ninja Forms &lt; 3.2.15 - Parameter Tampering","link":"https:\/\/wpscan.com\/vulnerability\/8c4f0824-6f50-4804-88ed-72617b2e339b","description":"The Ninja Forms Contact Form &ndash; The Drag and Drop Form Builder for WordPress WordPress plugin was affected by a Parameter Tampering security vulnerability.","date":null}],"impact":{"cvss":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:H\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"n","i":"h","a":"n","score":"7.5","severity":"h","exploitable":"3.9","impact":"3.6"},"cvss3":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:H\/A:N","score":"7.5","severity":"high","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"none","i":"high","a":"none","exploitable":"3.9","impact":"3.6"},"cwe":[{"cwe":"CWE-20","name":"Improper Input Validation","description":"The product receives input or data, but it does\n        not validate or incorrectly validates that the input has the\n        properties that are required to process the data safely and\n        correctly."}]}},{"uuid":"32835a6c70d226d96d1350fdc4b94a0bcf2fcdf292642f01259f3f3a623f8324","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.0.31","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.0.31","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2017-18574","name":"CVE-2017-18574","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2017-18574","description":"[en] The ninja-forms plugin before 3.0.31 for WordPress has insufficient HTML escaping in the builder.","date":"2019-08-22"},{"id":"29cf134867cc99b397f9b033146fde40783f4f2a","name":"Ninja Forms Contact Form \u2013 The Drag and Drop Form Builder for WordPress <= 3.0.30 - HTML Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ninja-forms\/ninja-forms-contact-form-the-drag-and-drop-form-builder-for-wordpress-3030-html-injection","description":"The ninja-forms plugin before 3.0.31 for WordPress has insufficient HTML escaping in the builder.","date":"2017-03-07"},{"id":"a7e69d72-5f26-44eb-ae57-ac7f56cdd5d5","name":"Ninja Forms &lt; 3.0.31 - XSS","link":"https:\/\/wpscan.com\/vulnerability\/a7e69d72-5f26-44eb-ae57-ac7f56cdd5d5","description":"The Ninja Forms Contact Form &ndash; The Drag and Drop Form Builder for WordPress WordPress plugin was affected by a XSS security vulnerability.","date":null}],"impact":{"cvss":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-20","name":"Improper Input Validation","description":"The product receives input or data, but it does\n        not validate or incorrectly validates that the input has the\n        properties that are required to process the data safely and\n        correctly."}]}},{"uuid":"361ed1252d603486156d86e39de8eaa25294647386246324cca0796468f93f2b","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.3.21.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.3.21.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2019-15025","name":"CVE-2019-15025","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2019-15025","description":"[en] The ninja-forms plugin before 3.3.21.2 for WordPress has SQL injection in the search filter on the submissions page.","date":"2019-08-14"},{"id":"5118897e76cc31628a1fe96ccddbd0ba00ff124e","name":"Ninja Forms Contact Form <= 3.3.21.1 - SQL Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ninja-forms\/ninja-forms-contact-form-33211-sql-injection","description":"The ninja-forms plugin before 3.3.21.2 for WordPress has SQL injection in the search filter on the submissions page.","date":"2019-01-07"},{"id":"3ce78586-9920-4faa-8efd-1e58d885457e","name":"Ninja Forms &lt; 3.3.21.2 - SQL Injection","link":"https:\/\/wpscan.com\/vulnerability\/3ce78586-9920-4faa-8efd-1e58d885457e","description":"The Ninja Forms Contact Form &ndash; The Drag and Drop Form Builder for WordPress WordPress plugin was affected by a SQL Injection security vulnerability.","date":null}],"impact":{"cvss":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"9.8","severity":"c","exploitable":"3.9","impact":"5.9"},"cvss3":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"9.8","severity":"critical","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"3.9","impact":"5.9"},"cwe":[{"cwe":"CWE-89","name":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')","description":"The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data."}]}},{"uuid":"1a4f0d467be5399fe15116c738db2dce7615980089e7ffebb3048b538020e620","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.3.19.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.3.19.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2018-19796","name":"CVE-2018-19796","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2018-19796","description":"[en] An open redirect in the Ninja Forms plugin before 3.3.19.1 for WordPress allows Remote Attackers to redirect a user via the lib\/StepProcessing\/step-processing.php (aka submissions download page) redirect parameter.","date":"2018-12-03"},{"id":"efaa953ee8e009108b682d6799c50d0c133694fc","name":"WordPress Ninja Forms plugin <= 3.3.19 - Authenticated Open Redirect vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ninja-forms\/vulnerability\/wordpress-ninja-forms-plugin-3-3-19-authenticated-open-redirect-vulnerability","description":"Authenticated Open Redirect vulnerability found by Muhammad Talha Khan in WordPress Ninja Forms plugin (versions <= 3.3.19).","date":"2018-12-04"},{"id":"c86cabf100577c7a8b5d66d4e132ef7c5b90d090","name":"Ninja Forms Contact Form <= 3.3.19 - Authenticated Open Redirect","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ninja-forms\/ninja-forms-contact-form-3319-authenticated-open-redirect","description":"An open redirect in the Ninja Forms plugin before 3.3.19.1 for WordPress allows Remote Attackers to redirect a user via the lib\/StepProcessing\/step-processing.php (aka submissions download page) redirect parameter.","date":"2018-12-01"},{"id":"02fa90e3-d846-4bbc-98f9-88dfcf4e2740","name":"Ninja Forms &lt;= 3.3.19 - Authenticated Open Redirect","link":"https:\/\/wpscan.com\/vulnerability\/02fa90e3-d846-4bbc-98f9-88dfcf4e2740","description":"Open Redirect vulnerability in download submission page using URL parameter.","date":null}],"impact":{"cvss":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-601","name":"URL Redirection to Untrusted Site ('Open Redirect')","description":"The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect."}]}},{"uuid":"dfdda7095401bee0ca478aad8ba9479188d4048463bd19ac68788333adb48936","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.3.18","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.3.18","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2018-19287","name":"CVE-2018-19287","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2018-19287","description":"[en] XSS in the Ninja Forms plugin before 3.3.18 for WordPress allows Remote Attackers to execute JavaScript via the includes\/Admin\/Menus\/Submissions.php (aka submissions page) begin_date, end_date, or form_id parameter.","date":"2018-11-15"},{"id":"e21cab93886b608585f8da947d9fdb0fe25ef4f2","name":"WordPress Ninja Forms plugin <= 3.3.17 - Unauthenticated Cross-Site Scripting (XSS) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ninja-forms\/vulnerability\/wordpress-ninja-forms-plugin-3-3-17-unauthenticated-cross-site-scripting-xss-vulnerability","description":"Unauthenticated Cross-Site Scripting (XSS) vulnerability found in WordPress Ninja Forms plugin (versions <= 3.3.17).","date":"2018-11-15"},{"id":"e1c7fb76bb657b133cc883e5baa1cd7ab4de9cc3","name":"Ninja Forms Contact Form <= 3.3.17 - Cross-Site Scripting via begin_date, end_date, or form_id Parameter","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ninja-forms\/ninja-forms-contact-form-3317-cross-site-scripting-via-begin-date-end-date-or-form-id-parameter","description":"XSS in the Ninja Forms plugin before 3.3.18 for WordPress allows Remote Attackers to execute JavaScript via the includes\/Admin\/Menus\/Submissions.php (aka submissions page) begin_date, end_date, or form_id parameter.","date":"2018-11-15"},{"id":"fb036dc2-0ee8-4a3e-afac-f52050b3f8c7","name":"Ninja Forms &lt;= 3.3.17 - Unauthenticated Cross-Site Scripting (XSS)","link":"https:\/\/wpscan.com\/vulnerability\/fb036dc2-0ee8-4a3e-afac-f52050b3f8c7","description":"According to the changelog:\r\n\r\n&quot;Patched a redirect XSS vulnerability using code injection on our submissions page.&quot;","date":null}],"impact":{"cvss":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"b133b72606dda59dc023e032a8ca7c56c897c2b5d192e15c98c52e1a3b21d1fd","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.3.14","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.3.14","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2018-16308","name":"CVE-2018-16308","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2018-16308","description":"[en] The Ninja Forms plugin before 3.3.14.1 for WordPress allows CSV injection.","date":"2018-09-01"},{"id":"7a477aba67f2d9b77584d12dcb8ae4df08e9817f","name":"Ninja Forms Contact Form <= 3.3.13 - CSV Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ninja-forms\/ninja-forms-contact-form-3313-csv-injection","description":"The Ninja Forms plugin before 3.3.14.1 for WordPress allows CSV injection.","date":"2018-08-19"},{"id":"02cc8296-5662-48dc-bafe-29074b25654f","name":"Ninja Forms &lt;= 3.3.13 - CSV Injection","link":"https:\/\/wpscan.com\/vulnerability\/02cc8296-5662-48dc-bafe-29074b25654f","description":"The Ninja Forms Contact Form &ndash; The Drag and Drop Form Builder for WordPress WordPress plugin was affected by a CSV Injection security vulnerability.","date":null}],"impact":{"cvss":{"version":"3.0","vector":"CVSS:3.0\/AV:L\/AC:L\/PR:N\/UI:R\/S:C\/C:H\/I:H\/A:H","av":"l","ac":"l","pr":"n","ui":"r","s":"c","c":"h","i":"h","a":"h","score":"8.6","severity":"h","exploitable":"1.8","impact":"6.0"},"cvss3":{"version":"3.0","vector":"CVSS:3.0\/AV:L\/AC:L\/PR:N\/UI:R\/S:C\/C:H\/I:H\/A:H","score":"8.6","severity":"high","av":"local","ac":"low","pr":"none","ui":"required","s":"changed","c":"high","i":"high","a":"high","exploitable":"1.8","impact":"6.0"},"cwe":[{"cwe":"CWE-1236","name":"Improper Neutralization of Formula Elements in a CSV File","description":"The product saves user-provided information into a Comma-Separated Value (CSV) file, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as a command when the file is opened by a spreadsheet product."}]}},{"uuid":"7cc981b0c8ee3f01bd0d7a1e82357d48a2474efc1de2330791cd7e754b7da06d","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.2.14","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.2.14","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2018-7280","name":"CVE-2018-7280","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2018-7280","description":"[en] The Ninja Forms plugin before 3.2.14 for WordPress has XSS.","date":"2018-02-21"},{"id":"ecd20a6e49a834b6c12d08b9f533d9c12d06d4f4","name":"WordPress Ninja Forms plugin <=3.2.13 - Cross-Site Scripting (XSS) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ninja-forms\/vulnerability\/wordpress-ninja-forms-plugin-3-2-13-cross-site-scripting-xss-vulnerability","description":"Cross-Site Scripting (XSS) vulnerability found by Kasper Karlsson in WordPress Ninja Forms plugin (versions <= 3.2.13).","date":"2018-02-22"},{"id":"6a68ed77c37cf9619ba1e462f49e6926cf2cf65c","name":"Ninja Forms Contact Form <= 3.2.13 - Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ninja-forms\/ninja-forms-contact-form-3213-cross-site-scripting","description":"The Ninja Forms plugin before 3.2.14 for WordPress has XSS.","date":"2018-02-20"},{"id":"48011651-4317-40c3-8d12-3a589a49129d","name":"Ninja Forms &lt;= 3.2.13 - Cross-Site Scripting (XSS)","link":"https:\/\/wpscan.com\/vulnerability\/48011651-4317-40c3-8d12-3a589a49129d","description":"The Ninja Forms Contact Form &ndash; The Drag and Drop Form Builder for WordPress WordPress plugin was affected by a Cross-Site Scripting (XSS) security vulnerability.","date":null}],"impact":{"cvss":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"ce00d4bf69bab923a17c32ac849675f4f980626b2efb28c03a49b3c84f1c494b","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] >= 2.9.36 - <= 2.9.42","description":null,"operator":{"min_version":"2.9.36","min_operator":"ge","max_version":"2.9.42","max_operator":"le","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2016-1209","name":"CVE-2016-1209","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2016-1209","description":"[en] The Ninja Forms plugin before 2.9.42.1 for WordPress allows remote attackers to conduct PHP object injection attacks via crafted serialized values in a POST request.","date":"2016-05-14"},{"id":"JVNDB-2016-000064","name":"WordPress plugin \"Ninja Forms\" vulnerable to PHP object injection","link":"http:\/\/jvndb.jvn.jp\/jvndb\/JVNDB-2016-000064","description":"WordPress plugin \"Ninja Forms\" contains a PHP object injection vulnerability due to a flaw where untrusted POST values are unserialized.","date":"2016-05-13"},{"id":"679fe322d56b737c0d5020fa733200174b19e8e4","name":"WordPress Ninja Forms Plugin <= 2.9.42.0 - PHP Object Injection","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ninja-forms\/vulnerability\/wordpress-ninja-forms-plugin-2-9-42-0-php-object-injection","description":"This vulnerability allows an attacker to conduct PHP object injection attacks via crafted serialized values in a POST request.\nUpdate the plugin.","date":"2015-12-26"},{"id":"226b156a0f89be80cd4486c98aa32c238150ac36","name":"Ninja Forms Contact Form 2.9.36 - 2.9.42 - PHP Object Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ninja-forms\/ninja-forms-contact-form-2936-2942-php-object-injection","description":"The Ninja Forms plugin before 2.9.42.1 for WordPress allows remote attackers to conduct PHP object injection attacks via crafted serialized values in a POST request.","date":"2016-05-13"},{"id":"46a947c9958606324d63e2809100ab31ec94043b","name":"Ninja Forms Contact Form 2.9.36 - 2.9.42 - Unauthenticated Arbitrary File Upload","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ninja-forms\/ninja-forms-contact-form-2936-2942-unauthenticated-arbitrary-file-upload","description":"Versions 2.9.36 to 2.9.42 of the Ninja Forms plugin contain an unauthenticated file upload vulnerability, allowing guests to upload arbitrary PHP code that can be executed in the context of the web server.","date":"2016-05-05"},{"id":"513fab31-d0e5-4d22-a7e3-63707e6e8aaa","name":"Ninja Forms 2.9.36 to 2.9.42 - Multiple Vulnerabilities","link":"https:\/\/wpscan.com\/vulnerability\/513fab31-d0e5-4d22-a7e3-63707e6e8aaa","description":"The Ninja Forms Contact Form &ndash; The Drag and Drop Form Builder for WordPress WordPress plugin was affected by a Multiple Vulnerabilities security vulnerability.","date":null}],"impact":{"cvss":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"9.8","severity":"c","exploitable":"3.9","impact":"5.9"},"cvss3":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"9.8","severity":"critical","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"3.9","impact":"5.9"},"cwe":[{"cwe":"CWE-20","name":"Improper Input Validation","description":"The product receives input or data, but it does\n        not validate or incorrectly validates that the input has the\n        properties that are required to process the data safely and\n        correctly."}]}},{"uuid":"904428309675feafce40a4bcccc95a409233538f2e9427cf74b3da7fa3c31951","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 2.8.10","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.8.10","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2014-9688","name":"CVE-2014-9688","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2014-9688","description":"[en] Unspecified vulnerability in the Ninja Forms plugin before 2.8.10 for WordPress has unknown impact and remote attack vectors related to admin users.","date":"2015-03-05"},{"id":"189a608868b68fbd29e7f8056b7c5653ac0ebe7c","name":"WordPress Ninja Forms Plugin <= 2.8.9 - Unspecified Vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ninja-forms\/vulnerability\/wordpress-ninja-forms-plugin-2-8-9-unspecified-vulnerability","description":"Because of this vulnerability in Ninja Forms plugin, remote attack vectors are related to admin users.\nUpdate the plugin.","date":"2015-03-05"},{"id":"68cfcf86eb3bb04b57a21965dabbd20532c6ad9e","name":"Ninja Forms Contact Form \u2013 The Drag and Drop Form Builder for WordPress <= 2.8.8 - Reflected Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ninja-forms\/ninja-forms-contact-form-the-drag-and-drop-form-builder-for-wordpress-288-reflected-cross-site-scripting","description":"The Ninja Forms Contact Form \u2013 The Drag and Drop Form Builder for WordPress for WordPress is vulnerable to Reflected Cross-Site Scripting via the \u2018ninja_forms_field_1\u2019 parameter in versions up to, and including, 2.8.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.","date":"2014-12-02"},{"id":"26d23a24-57ef-427a-8f18-17eda757803c","name":"Ninja Forms &lt;= 2.8.9 - Unspecified Issue Affecting Admin Users","link":"https:\/\/wpscan.com\/vulnerability\/26d23a24-57ef-427a-8f18-17eda757803c","description":"This version includes a fix for a potential security vulnerability for admin users.","date":null}],"impact":{"cvss":{"version":null,"vector":null,"av":null,"ac":null,"pr":null,"ui":null,"s":null,"c":null,"i":null,"a":null,"score":"0.0","severity":null,"exploitable":"0.0","impact":"0.0"}}},{"uuid":"746e5477b46ab47b5af2114acea6a091aa963bec927b16fbaf2585b55272fb02","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 2.8.9","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.8.9","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2015-2220","name":"CVE-2015-2220","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2015-2220","description":"[en] Multiple cross-site scripting (XSS) vulnerabilities in the Ninja Forms plugin before 2.8.9 for WordPress allow (1) remote attackers to inject arbitrary web script or HTML via the ninja_forms_field_1 parameter in a ninja_forms_ajax_submit action to wp-admin\/admin-ajax.php or (2) remote administrators to inject arbitrary web script or HTML via the fields[1] parameter to wp-admin\/post.php.","date":"2015-03-05"},{"id":"797901ccc2353f9d6dfe5719d6b522d1f50e8cab","name":"WordPress Ninja Forms Plugin <= 2.8.8 - Multiple XSS","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ninja-forms\/vulnerability\/wordpress-ninja-forms-plugin-2-8-8-multiple-xss","description":"Because of these vulnerabilities, the attackers can inject arbitrary web script or HTML via the \"ninja_forms_field_1\" parameter in a ninja_forms_ajax_submit action to wp-admin\/admin-ajax.php. Also, multiple cross site scripting vulnerabilities allow the administrators to inject arbitrary web script or HTML via the \"fields[1]\" parameter to wp-admin\/post.php.\nUpdate the plugin.","date":"2015-03-05"},{"id":"8250c4e7c126b5321a2123869991a72f6ada4d38","name":"Ninja Forms Contact Form <= 2.8.8 - Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ninja-forms\/ninja-forms-contact-form-288-stored-cross-site-scripting","description":"Multiple cross-site scripting (XSS) vulnerabilities in the Ninja Forms plugin before 2.8.9 for WordPress allow (1) remote attackers to inject arbitrary web script or HTML via the ninja_forms_field_1 parameter in a ninja_forms_ajax_submit action to wp-admin\/admin-ajax.php or (2) remote administrators to inject arbitrary web script or HTML via the fields[1] parameter to wp-admin\/post.php.","date":"2014-11-20"},{"id":"cd629ff3-c238-4511-8438-221941423c48","name":"Ninja Forms &lt;= 2.8.8 - Stored &amp; Reflected XSS","link":"https:\/\/wpscan.com\/vulnerability\/cd629ff3-c238-4511-8438-221941423c48","description":"The Ninja Forms Contact Form &ndash; The Drag and Drop Form Builder for WordPress WordPress plugin was affected by a Stored &amp; Reflected XSS security vulnerability.","date":null}],"impact":{"cvss":{"version":null,"vector":null,"av":null,"ac":null,"pr":null,"ui":null,"s":null,"c":null,"i":null,"a":null,"score":"0.0","severity":null,"exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"bf0edcd045994906c3c598ffaf8821b4f287a515a85b8d2e85489d4f7fe04b84","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.6.8","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.6.8","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"75bab3d93feeb6aa3802dc7683d145a058edfd8b","name":"WordPress Ninja Forms plugin <= 3.6.7 - Unauthenticated Email Address Disclosure vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ninja-forms\/vulnerability\/wordpress-ninja-forms-plugin-3-6-7-unauthenticated-email-address-disclosure-vulnerability","description":"Unauthenticated Email Address Disclosure vulnerability discovered by Agence Web Coheractio in WordPress Ninja Forms plugin (versions <= 3.6.7).","date":"2022-03-22"}],"impact":[]},{"uuid":"5c05be6ea9c3cbfb251e86cd5a0ba656c80693393cb1903f4376d694bb8b96c6","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.4.34","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.4.34","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"8814fbe519d0ae2de82a6b8c3aae02f1e350852d","name":"WordPress Ninja Forms Contact Form plugin <= 3.4.33 - Cross-Site Request Forgery (CSRF) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ninja-forms\/vulnerability\/wordpress-ninja-forms-contact-form-plugin-3-4-33-cross-site-request-forgery-csrf-vulnerability","description":"Cross-Site Request Forgery (CSRF) vulnerability found by Chloe Chamberland in WordPress Ninja Forms Contact Form plugin (versions <= 3.4.33).","date":"2021-02-16"}],"impact":[]},{"uuid":"74f66630f13b9b80573055fcc5b49938be15f8c6e1e9ed39f67378c853e28a97","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.4.34","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.4.34","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"6362e851e00b374ca3099ade770798fd41e570ce","name":"WordPress Ninja Forms Contact Form plugin <= 3.4.33 - Administrator Open Redirect vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ninja-forms\/vulnerability\/wordpress-ninja-forms-contact-form-plugin-3-4-33-administrator-open-redirect-vulnerability","description":"Administrator Open Redirect vulnerability found by Chloe Chamberland in WordPress Ninja Forms Contact Form plugin (versions <= 3.4.33).","date":"2021-02-16"}],"impact":[]},{"uuid":"cb7a48cd83f42cefd6f9793dcd195a3ca429d996b4210242a4b024d5d82ea3fa","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.4.34","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.4.34","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"6c18b14c0c353cf9105f9102eea21f6bbad609c9","name":"WordPress Ninja Forms Contact Form plugin <= 3.4.33 - Authenticated OAuth Connection Key Disclosure vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ninja-forms\/vulnerability\/wordpress-ninja-forms-contact-form-plugin-3-4-33-authenticated-oauth-connection-key-disclosure-vulnerability","description":"Authenticated OAuth Connection Key Disclosure vulnerability found by Chloe Chamberland in WordPress Ninja Forms Contact Form plugin (versions <= 3.4.33).","date":"2021-02-16"}],"impact":[]},{"uuid":"3528042f3f64d754151d9f8fdc2f4b4d4d64603fd63ab5e5f0530ba3423cfafe","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.4.34","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.4.34","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"97c8efa05613e39107ff483222451ad3fd30e590","name":"WordPress Ninja Forms Contact Form plugin <= 3.4.33 - Authenticated SendWP Plugin Installation and Client Secret Key Disclosure vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ninja-forms\/vulnerability\/wordpress-ninja-forms-contact-form-plugin-3-4-33-authenticated-sendwp-plugin-installation-and-client-secret-key-disclosure-vulnerability","description":"Authenticated SendWP Plugin Installation and Client Secret Key Disclosure vulnerability found by Chloe Chamberland in WordPress Ninja Forms Contact Form plugin (versions <= 3.4.33).","date":"2021-02-16"}],"impact":[]},{"uuid":"6b7e52d070ebbf45ea7680cd4a1b6fae23e9829626b187e224ca827a3765f311","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.4.27.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.4.27.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"f815fadab1550c44ce7eabd76f9d3a6bfb0e7524","name":"WordPress Ninja Forms plugin <= 3.4.27 - Cross-Site Request Forgery (CSRF) leading to Arbitrary Plugin Installation vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ninja-forms\/vulnerability\/wordpress-ninja-forms-plugin-3-4-27-cross-site-request-forgery-csrf-leading-to-arbitrary-plugin-installation-vulnerability","description":"Cross-Site Request Forgery (CSRF) leading to Arbitrary Plugin Installation vulnerability found by Slavco Mihajloski in WordPress Ninja Forms plugin (versions <= 3.4.27).","date":"2020-09-22"}],"impact":[]},{"uuid":"2d1eed183b0c0931534dee0c4ea344ab8a83c84a1769f41f273177c46213496d","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.3.21.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.3.21.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"1983ed4b8251c56d274067560a67a5a1106e1b18","name":"WordPress Ninja Forms plugin <= 3.3.21 - Cross-Site Scripting (XSS) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ninja-forms\/vulnerability\/wordpress-ninja-forms-plugin-3-3-21-cross-site-scripting-xss-vulnerability","description":"Cross-Site Scripting (XSS) vulnerability found in WordPress Ninja Forms plugin (versions <= 3.3.21).","date":"2019-06-25"}],"impact":[]},{"uuid":"6b517c2b26bd28e71158b7c83525122259b79d97f1fb0c62aff3ea1c7337e89f","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.3.21.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.3.21.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"c08677aed644ad9abd1f6777af407fb61f0b1746","name":"WordPress Ninja Forms plugin <= 3.3.21 - SQL injection (SQLi) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ninja-forms\/vulnerability\/wordpress-ninja-forms-plugin-3-3-21-sql-injection-sqli-vulnerability","description":"SQL injection (SQLi) vulnerability found in WordPress Ninja Forms plugin (versions <= 3.3.21).","date":"2019-06-25"}],"impact":[]},{"uuid":"c41aa9399c18d6e8c846de4f4d559f065bc7d85c92defdde6878afa0db1ba6c9","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.3.14","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.3.14","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"62e22fe8163168a9aa45945f81c33955375f669e","name":"WordPress Ninja Forms plugin <= 3.3.13 - CSV Injection vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ninja-forms\/vulnerability\/wordpress-ninja-forms-plugin-3-3-13-csv-injection-vulnerability","description":"CSV Injection vulnerability fund by Mostafa Gharzi in WordPress Ninja Forms plugin (versions <= 3.3.13).","date":"2018-08-28"}],"impact":[]},{"uuid":"421e0659b58b7c1617bea27270581d231b1ded8b42eca4af3f92b791f344bad5","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.3.14","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.3.14","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"8ed0fce1003899b0e7622e875f01c25d26bf20a9","name":"WordPress Ninja Forms plugin <= 3.3.13 - Cross-Site Scripting (XSS) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ninja-forms\/vulnerability\/wordpress-ninja-forms-plugin-3-3-13-cross-site-scripting-xss-vulnerability","description":"Cross-Site Scripting (XSS) vulnerability found in WordPress Ninja Forms plugin (versions <= 3.3.13).","date":"2018-08-28"}],"impact":[]},{"uuid":"6d605792ba1bbf1258db4ad863fb7cb57765e36fea3ad3dda83dd770466012c9","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 2.9.55.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.9.55.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"c6722c6bd80a41a9f5e55c8860889e4095aeffb0","name":"WordPress Ninja Forms Plugin <= 2.9.55.1 - Authenticated SQL Injection","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ninja-forms\/vulnerability\/wordpress-ninja-forms-plugin-2-9-55-1-authenticated-sql-injection","description":"There is a bug in this plugin. It could leak the site\u2019s usernames and hashed passwords.\nUpdate the plugin.","date":"2016-08-16"}],"impact":[]},{"uuid":"c1340eba5cd8e86762cf10a12e9c166dc16d79e3fd484df4f1a9ab427ab9d694","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 2.9.52","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.9.52","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"6b719ff83199e1e612a77d8e095bab815a0b8dfe","name":"WordPress Ninja Forms Plugin <= 2.9.51 - Multiple Cross Site Scripting","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ninja-forms\/vulnerability\/wordpress-ninja-forms-plugin-2-9-51-multiple-cross-site-scripting","description":"Because of this vulnerability, attackers can inject malicious JavaScript code into the application.\nUpdate this plugin.","date":"2016-07-19"}],"impact":[]},{"uuid":"325dde6c2ae23d7c7fb6fddb1aee002a02a4bf877ceada373b92ed4aa95abf73","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.6.10","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.6.10","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2021-25056","name":"CVE-2021-25056","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2021-25056","description":"[en] The Ninja Forms Contact Form WordPress plugin before 3.6.10 does not sanitise and escape field labels, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.","date":"2022-07-04"},{"id":"65f7a2a490ce309fada7078d4a82733d83936147","name":"WordPress Ninja Forms plugin <= 3.6.9 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ninja-forms\/vulnerability\/wordpress-ninja-forms-plugin-3-6-9-authenticated-stored-cross-site-scripting-xss-vulnerability-2","description":"Authenticated Stored Cross-Site Scripting (XSS) vulnerability discovered by Muhammad Adel WordPress Ninja Forms plugin (versions <= 3.6.9).\nUpdate the WordPress Ninja Forms plugin to the latest available version (at least 3.6.10).","date":"2022-06-13"},{"id":"b9b0cb07c2958c951a12b80b5998217f9caaaacd","name":"Ninja Forms Contact Form <= 3.6.9 - Cross-Site Scripting via field label","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ninja-forms\/ninja-forms-contact-form-369-cross-site-scripting-via-field-label","description":"The Ninja Forms Contact Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via field labels in versions up to, and including, 3.6.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrative level permissions and above to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.","date":"2022-06-13"},{"id":"795acab2-f621-4662-834b-ebb6205ef7de","name":"Ninja Forms &lt; 3.6.10 - Admin+ Stored Cross-Site Scripting","link":"https:\/\/wpscan.com\/vulnerability\/795acab2-f621-4662-834b-ebb6205ef7de","description":"The plugin does not sanitise and escape field labels, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"h","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"4.8","severity":"m","exploitable":"1.7","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"4.8","severity":"medium","av":"network","ac":"low","pr":"high","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"1.7","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"d3fa74427dbc05299f58ba6e64f585791fabdd0421b0d321b5529b97ce08e555","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 2.9.28","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.9.28","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"44611624527c30088b5dc0ee35f92f28ce05427b","name":"WordPress Ninja Forms Plugin <= 2.9.27 - Malicious File Export","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ninja-forms\/vulnerability\/wordpress-ninja-forms-plugin-2-9-27-malicious-file-export","description":"There is an unknown vulnerability in this plugin.\nUpgrade this plugin.","date":"2015-09-30"}],"impact":[]},{"uuid":"39284b53d6ac2d90b0fbe75a644c3dea7a218ab487ff955b84f4a1fe5abd9fe6","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] <= 3.6.10","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.6.10","max_operator":"le","unfixed":"0","closed":"0"},"source":[{"id":"7a7ae6840be2b22784ca13d3564a1dca63d26055","name":"WordPress Ninja Forms plugin <= 3.6.10 - Unauthenticated PHP Object Injection vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ninja-forms\/vulnerability\/wordpress-ninja-forms-plugin-3-6-10-unauthenticated-php-object-injection-vulnerability","description":"Unauthenticated PHP Object Injection vulnerability discovered in WordPress Ninja Forms plugin (versions <= 3.6.10).\nUpdate the WordPress Ninja Forms plugin to the latest available version (at least 3.6.11).","date":"2022-06-15"}],"impact":[]},{"uuid":"7a907424dc63619d941f48cfb72ccdbb7a11c6deea4edb2df10b1ebf191228c9","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 2.9.22","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.9.22","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"1653e6eaad668bd925e29c77b85c0abfaf421ab9","name":"WordPress Ninja Forms Plugin <= 2.9.21 - Cross Site Scripting","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ninja-forms\/vulnerability\/wordpress-ninja-forms-plugin-2-9-21-cross-site-scripting","description":"Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code.\nUpdate the plugin.","date":"2015-08-04"}],"impact":[]},{"uuid":"930c47d0ad59decea1f651db16eeb38c8ffe8f759e23873910e68a778930bf88","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.6.10","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.6.10","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2021-36827","name":"CVE-2021-36827","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2021-36827","description":"[en] Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Saturday Drive's Ninja Forms Contact Form plugin <= 3.6.9 at WordPress via \"label\".","date":"2022-06-16"},{"id":"81b638890ff24152d0d27b1f2c918152ea8581d2","name":"WordPress Ninja Forms Contact Form plugin <= 3.6.9 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ninja-forms\/vulnerability\/wordpress-ninja-forms-contact-form-plugin-3-6-9-authenticated-stored-cross-site-scripting-xss-vulnerability","description":"Authenticated Stored Cross-Site Scripting (XSS) vulnerability discovered by Asif Nawaz Minhas (Patchstack Alliance) in WordPress Ninja Forms Contact Form plugin (versions <= 3.6.9).\nUpdate the WordPress Ninja Forms Contact Form plugin to the latest available version (at least 3.6.10).","date":"2022-06-07"},{"id":"ab0913204f15ef85c3428a6007e3f9c336130915","name":"Ninja Forms Contact Form <= 3.6.9 - Authenticated (Admin+) Cross-Site Scripting via label","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ninja-forms\/ninja-forms-contact-form-369-authenticated-admin-cross-site-scripting-via-label","description":"The Ninja Forms Contact Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'label' parameter in versions up to, and including, 3.6.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrative level permissions and above to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.","date":"2022-06-07"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"h","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"4.8","severity":"m","exploitable":"1.7","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"4.8","severity":"medium","av":"network","ac":"low","pr":"high","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"1.7","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"f229c0829a389d416ca887685b9b75121d40417d843f3a27af9138918805ac00","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 2.9.19","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.9.19","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"5e24776f52ce6209a0bfdb73a1eec92de49e8179","name":"WordPress Ninja Forms Plugin <= 2.9.18 - Cross Site Scripting","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ninja-forms\/vulnerability\/wordpress-ninja-forms-plugin-2-9-18-cross-site-scripting","description":"Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code.\nUpdate the plugin.","date":"2015-06-05"}],"impact":[]},{"uuid":"849aa8063f16ea90922cead3300ccbf2c4eb70bb320fed979435646fb94dcaca","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.6.11","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.6.11","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2021-25066","name":"CVE-2021-25066","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2021-25066","description":"[en] The Ninja Forms Contact Form WordPress plugin before 3.6.10 does not sanitize and escape some imported data, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.","date":"2022-07-04"},{"id":"2627d76a90513eeaf28c348f6e43df3870f5d046","name":"WordPress Ninja Forms plugin <= 3.6.9 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ninja-forms\/vulnerability\/wordpress-ninja-forms-plugin-3-6-9-authenticated-stored-cross-site-scripting-xss-vulnerability","description":"Authenticated Stored Cross-Site Scripting (XSS) vulnerability discovered by Muhammad Adel in WordPress Ninja Forms plugin (versions <= 3.6.9).\nUpdate the WordPress Ninja Forms plugin to the latest available version (at least 3.6.10).","date":"2022-06-10"},{"id":"cd4341ecd59fe053f3101b929a9d9d01d5a071bc","name":"Ninja Ninja Forms Contact Form <= 3.6.10 - Authenticated (Admin+) Stored Cross-Site Scripting via import","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ninja-forms\/ninja-ninja-forms-contact-form-3610-authenticated-admin-stored-cross-site-scripting-via-import","description":"The Ninja Forms Contact Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters found in an import in versions up to, and including, 3.6.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrative level permissions and above to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.","date":"2022-06-10"},{"id":"323d5fd0-abe8-44ef-9127-eea6fd4f3f3d","name":"Ninja Forms &lt; 3.6.10 - Admin+ Stored Cross-Site Scripting via Import","link":"https:\/\/wpscan.com\/vulnerability\/323d5fd0-abe8-44ef-9127-eea6fd4f3f3d","description":"The plugin does not sanitize and escape some imported data, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"h","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"4.8","severity":"m","exploitable":"1.7","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"4.8","severity":"medium","av":"network","ac":"low","pr":"high","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"1.7","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"7541da2efeebc906ed21fe4a888a46d3d51a0388f6ec31cd2d4795d02ede099b","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 2.7.8","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.7.8","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"165ba9a9422d8ed51d0905bb36cbc8aac59737b6","name":"WordPress Ninja Forms Plugin - Authorization Bypass","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ninja-forms\/vulnerability\/wordpress-ninja-forms-plugin-authorization-bypass","description":"Ninja Forms plugin is prone to an authorization BYPASS vulnerability that allows an attacker to bypass  security restrictions and perform unauthorized actions.\nUpdate the plugin.","date":"2014-09-08"}],"impact":[]},{"uuid":"b0eba483c1a892a0f8ab49584db0442d43ad86038f592eda86f85db76c542561","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 2.9.11","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.9.11","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"646a679abf35dc7c80910f05a6a2657cd7abb6c1","name":"WordPress Ninja Forms Plugin <= 2.9.10 - Cross Site Scripting","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ninja-forms\/vulnerability\/wordpress-ninja-forms-plugin-2-9-10-cross-site-scripting","description":"Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code.\nUpgrade the plugin.","date":"2015-04-20"}],"impact":[]},{"uuid":"4f21948c90b3f91ae3658bd681f33859f5ab089aa45ed392d68fa05a17878898","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.6.13","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.6.13","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2022-2903","name":"CVE-2022-2903","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-2903","description":"[en] The Ninja Forms Contact Form WordPress plugin before 3.6.13 unserialises the content of an imported file, which could lead to PHP object injections issues when an admin import (intentionally or not) a malicious file and a suitable gadget chain is present on the blog.","date":"2022-09-26"},{"id":"c1987726bbfcdc08d98fb5d4645a26e101e14413","name":"WordPress NinjaForms plugin <= 3.6.12 - Authenticated PHP Objection Injection vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ninja-forms\/vulnerability\/wordpress-ninjaforms-plugin-3-6-12-authenticated-php-objection-injection-vulnerability","description":"Authenticated PHP Objection Injection vulnerability discovered by Alessio Santoru in WordPress NinjaForms plugin (versions <= 3.6.12).\nUpdate the WordPress Ninja Forms plugin to the latest available version (at least 3.6.13).","date":"2022-09-05"},{"id":"69bc33567e134e90cca575a8db01f699efaced61","name":"Ninja Forms Contact Form \u2013 The Drag and Drop Form Builder for WordPress <= 3.6.12 - Authenticated (Administrator+) PHP Objection Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ninja-forms\/ninja-forms-contact-form-the-drag-and-drop-form-builder-for-wordpress-3612-authenticated-administrator-php-objection-injection","description":"The Ninja Forms Contact Form \u2013 The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.6.12  via deserialization of untrusted input. This allows administrator-level attackers to inject a PHP Object. No POP chain is present in the vulnerable NinjaForms. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.","date":"2022-09-05"},{"id":"255b98ba-5da9-4424-a7e9-c438d8905864","name":"NinjaForms &lt; 3.6.13 - Admin+ PHP Objection Injection","link":"https:\/\/wpscan.com\/vulnerability\/255b98ba-5da9-4424-a7e9-c438d8905864","description":"The plugin unserialises the content of an imported file, which could lead to PHP object injections issues when an admin import (intentionally or not) a malicious file and a suitable gadget chain is present on the blog.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"h","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"7.2","severity":"h","exploitable":"1.2","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"7.2","severity":"high","av":"network","ac":"low","pr":"high","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"1.2","impact":"5.9"},"cwe":[{"cwe":"CWE-502","name":"Deserialization of Untrusted Data","description":"The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid."}],"ssvc":{"exploitation":"poc","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"d9e8dbdac5ff9aabbb62896c526e5b6b66c0f1e2bc9bd9d4dea49c2bde095d6f","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.6.11","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.6.11","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"cc43d8f4fa796879a20d51bcee8882361a17f7ed","name":"Ninja Forms Contact Form \u2013 The Drag and Drop Form Builder for WordPress <= 3.6.10 - Code Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ninja-forms\/ninja-forms-contact-form-the-drag-and-drop-form-builder-for-wordpress-3610-code-injection","description":"The Ninja Forms Contact Form \u2013 The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to code injection in versions up to, and including 3.6.10 due to insufficient validation on Merge Tags that makes it possible to call arbitrary Ninja Form classes. This could lead to a variety of actions, however, one notable one is deserialization when the NF_Admin_Processes_ImportForm::startup method is called.  On sites with a POP chain this could be used to achieve remote code execution in the worst possible scenarios.","date":"2022-06-15"}],"impact":[]},{"uuid":"e12296e7d8c1f13c120c877168516640738b3680e726edf7fe89ce1fb293c06b","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.6.10","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.6.10","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"d95c22bf19ccb520b61bb7864bc8c03e52e2d88c","name":"Ninja Forms Contact Form \u2013 The Drag and Drop Form Builder for WordPress <= 3.6.9 - Cross-Site Request Forgery to Field Import and PHP Object Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ninja-forms\/ninja-forms-contact-form-the-drag-and-drop-form-builder-for-wordpress-369-cross-site-request-forgery-to-field-import-and-php-object-injection","description":"The Ninja Forms Contact Form \u2013 The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including 3.6.9, due to missing nonce validation on the import_fields_listener() function that makes it possible for unauthenticated attackers to import new form fields granted that can trick an attacker into performing an action such as clicking on a link.\r\n\r\nThis CSRF vulnerability can also be exploited to achieve PHP Object Injection due to the use of unserialize() on the user supplied file contents.","date":"2022-06-07"}],"impact":[]},{"uuid":"f453da46f4710c26f1d3bb33b0f8b1626feeb6215f62d3e4a2aa54a8b12143c8","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.6.8","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.6.8","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"285248894cf3f46268dd01b511e7be621b633209","name":"Ninja Forms Contact Form \u2013 The Drag and Drop Form Builder for WordPress <= 3.6.7 - Email Address Disclosure","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ninja-forms\/ninja-forms-contact-form-the-drag-and-drop-form-builder-for-wordpress-367-email-address-disclosure","description":"The Ninja Forms Contact Form \u2013 The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 3.6.7. This can allow unauthenticated attackers to extract sensitive data including other users' email addresses which can be used to help perform future attacks.","date":"2022-03-22"}],"impact":[]},{"uuid":"e3777da2fe18fe4c1bb1e4091c908b8c537bc5df23acc4dffcb0844e93a91451","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.3.14","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.3.14","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"897115ff2e79aea9d4fbc14733f0a1df9e9a557a","name":"Ninja Forms Contact Form \u2013 The Drag and Drop Form Builder for WordPress <= 3.3.13 - Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ninja-forms\/ninja-forms-contact-form-the-drag-and-drop-form-builder-for-wordpress-3313-cross-site-scripting","description":"The Ninja Forms Contact Form \u2013 The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Cross-Site Scripting via the form input function in versions up to, and including, 3.3.13 due to insufficient input sanitization and output escaping. This makes it possible for  attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2018-08-27"}],"impact":[]},{"uuid":"c0cd88ff8e3a8c1b215ba6dac407564e40142d6f04ca2b45e028f130a67618e4","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.0.32","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.0.32","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"0bc642976d29821d5fd23074ac0888a4976b0eab","name":"Ninja Forms Contact Form \u2013 The Drag and Drop Form Builder for WordPress <= 3.0.31 - Arbitrary Wordpress Shortcode Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ninja-forms\/ninja-forms-contact-form-the-drag-and-drop-form-builder-for-wordpress-3031-arbitrary-wordpress-shortcode-injection","description":"The Ninja Forms Contact Form \u2013 The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Arbitrary Wordpress Shortcode Injection in versions up to, and including, 3.0.31. This makes it possible for unauthenticated attackers to preview un-published forms and could possibly be used to leverage further attacks.","date":"2017-04-17"}],"impact":[]},{"uuid":"9b536c57b02e265b76e26fb776a9c211cd050544e4af86500d673dc86564ccdc","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 2.9.55.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.9.55.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"5b398fa56cafc9d3c602ad3cdf4ac8bf17e8be2d","name":"Ninja Forms Contact Form <= 2.9.55.1 - Authenticated SQL Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ninja-forms\/ninja-forms-contact-form-29551-authenticated-sql-injection","description":"The Ninja Forms Contact Form plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.9.55.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for Subscriber-level attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.","date":"2016-08-16"}],"impact":[]},{"uuid":"3c870c49ddfde3f9941c6779fcf3019c2d72f812f6deb64b55cb5b0834ce7783","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 2.9.52","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.9.52","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"b2c9b7bc99d03823fc8c26e4a668f61748a955a8","name":"Ninja Forms Contact Form <= 2.9.51 - Multiple Reflected Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ninja-forms\/ninja-forms-contact-form-2951-multiple-reflected-cross-site-scripting","description":"The Ninja Forms Contact Form plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via multiple parameters in versions before 2.9.52 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.","date":"2016-07-19"}],"impact":[]},{"uuid":"4db7cc09c18f6d3995e68049336803d87cd6e05e6f65ab14971eb780f96b2cdb","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 2.9.29","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.9.29","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"f456817941a1bba1744a5a404546997b68d0dd43","name":"Ninja Forms Contact Form <= 2.9.28 - Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ninja-forms\/ninja-forms-contact-form-2928-stored-cross-site-scripting","description":"The Ninja Forms Contact Form plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 2.9.28 due to insufficient input sanitization and output escaping during form submission. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.","date":"2015-12-08"}],"impact":[]},{"uuid":"47a63aa74bef3f44fb639da8978c2bb09208b8d976df08ff70036f1646b47ebc","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 2.9.28","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.9.28","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"4d4dec44bed3364eeef20d4c24615d186947040c","name":"Ninja Forms Contact Form <= 2.9.27 - CSV Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ninja-forms\/ninja-forms-contact-form-2927-csv-injection","description":"The Ninja Forms Contact Form plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 2.9.27 via the export() function. This allows authenticated attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on a local system with a vulnerable configuration.","date":"2015-09-30"}],"impact":[]},{"uuid":"ea8f8ecef7310c1ff026d7683ece42a09e58937e88d717eee8fabdaaddb8948a","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 2.9.22","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.9.22","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"2d7b56a3ba05e8ba90e4bb0d2b0979d98f560240","name":"Ninja Forms Contact Form <= 2.9.21 - Reflected Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ninja-forms\/ninja-forms-contact-form-2921-reflected-cross-site-scripting","description":"The Ninja Forms Contact Form plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.9.21 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.","date":"2015-08-04"}],"impact":[]},{"uuid":"a63cd7a2af7f50eff365e5db5b1ae15f6c86e57a5c52470263d6d708da45c4e1","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 2.9.19","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.9.19","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"b84c1dcccc9b9a3c55a57523da9e43d8134d022b","name":"Ninja Forms Contact Form <= 2.9.18 - Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ninja-forms\/ninja-forms-contact-form-2918-cross-site-scripting","description":"The Ninja Forms Contact Form plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 2.9.18 due to insufficient input sanitization and output escaping. This makes it possible for unauthorized attackers to inject arbitrary web scripts that execute in a victim's browser.","date":"2015-06-05"}],"impact":[]},{"uuid":"e9c382e09a7e71fb4285ae6d559dd2f5ab1b9e9a4fb02e9b1dacb3a739a47df5","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 2.9.11","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.9.11","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"4d853456ce172f350a9d0a401ea82c05e7ce461c","name":"Ninja Forms <= 2.9.10 - Reflected Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ninja-forms\/ninja-forms-2910-reflected-cross-site-scripting","description":"The Ninja Forms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.9.10 due to insufficient input sanitization and output escaping on add_query_arg and remove_query_arg. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.","date":"2015-04-20"}],"impact":[]},{"uuid":"e05a0f29b99716e778c2d3b6792c1496a35db38befff8f3b1b09cdc25bf7d26b","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 2.8.7","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.8.7","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2014-8815","name":"CVE-2014-8815","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2014-8815","description":"** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.","date":"0000-00-00"},{"id":"c88c43569e81d71bd8346be971376755391d9309","name":"Ninja Forms Contact Form \u2013 The Drag and Drop Form Builder for WordPress <= 2.8.6 - Reflected Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ninja-forms\/ninja-forms-contact-form-the-drag-and-drop-form-builder-for-wordpress-286-reflected-cross-site-scripting","description":"The Ninja Forms Contact Form \u2013 The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the \u2018update_message\u2019 parameter in versions up to, and including, 2.8.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.","date":"2014-11-06"},{"id":"42227853-fe96-456a-9f48-7829e0a643f5","name":"Ninja Forms 2.8.6 - Reflected Cross-Site Scripting (XSS)","link":"https:\/\/wpscan.com\/vulnerability\/42227853-fe96-456a-9f48-7829e0a643f5","description":"The Ninja Forms Contact Form &ndash; The Drag and Drop Form Builder for WordPress WordPress plugin was affected by a Reflected Cross-Site Scripting (XSS) security vulnerability.","date":null}],"impact":[]},{"uuid":"20800d131cbfcf535594ec7fe3210fc279664e5565b0b36d2a0a4f608adc1d72","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.6.22","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.6.22","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-1835","name":"CVE-2023-1835","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-1835","description":"[en] The Ninja Forms Contact Form WordPress plugin before 3.6.22 does not properly escape user input before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin","date":"2023-05-15"},{"id":"ba4db3a2680e8b42d0a2e27cb64e44b0c2fec527","name":"WordPress  Ninja Forms Plugin  < 3.6.22 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ninja-forms\/vulnerability\/wordpress-ninja-forms-plugin-3-6-22-reflected-xss-vulnerability","description":"Update the WordPress Ninja Forms plugin to the latest available version (at least 3.6.22).\nErwan LR (WPScan) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Ninja Forms Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.  This vulnerability has been fixed in version 3.6.22.","date":"2023-05-02"},{"id":"14a9e6ec2ecbce9058fad3ff2b2fa17475f4b3fe","name":"Ninja Forms Contact Form <= 3.6.21 - Reflected Cross-Site Scripting via 'title'","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ninja-forms\/ninja-forms-contact-form-3621-reflected-cross-site-scripting-via-title","description":"The Ninja Forms Contact Form plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'title' parameter in versions up to, and including, 3.6.21 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.","date":"2023-04-24"},{"id":"b5fc223c-5ec0-44b2-b2f6-b35f9942d341","name":"Ninja Forms &lt; 3.6.22 - Reflected XSS","link":"https:\/\/wpscan.com\/vulnerability\/b5fc223c-5ec0-44b2-b2f6-b35f9942d341","description":"The plugin does not properly escape user input before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"poc","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"bd1196414ee7b25a337873343406a9dad377aad3b28d5688b582f25db1a35d17","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.6.25","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.6.25","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-36505","name":"CVE-2023-36505","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-36505","description":"[en] Improper Input Validation vulnerability in Saturday Drive Ninja Forms Contact Form.This issue affects Ninja Forms Contact Form : from n\/a through 3.6.24.","date":"2024-04-17"},{"id":"34073ee05fe59a92f158535eda84f68799a85bd1","name":"WordPress  Ninja Forms Plugin  <= 3.6.24 is vulnerable to Arbitrary File Deletion","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ninja-forms\/vulnerability\/wordpress-ninja-forms-contact-form-the-drag-and-drop-form-builder-for-wordpress-plugin-3-6-24-arbitrary-file-deletion-vulnerability","description":"Update the WordPress Ninja Forms plugin to the latest available version (at least 3.6.25).\nTheodoros Malachias discovered and reported this Arbitrary File Deletion vulnerability in WordPress Ninja Forms Plugin. This could allow a malicious actor to delete files from your website. If core files are deleted from your website, it could cause your site to break and stop functioning. This vulnerability has been fixed in version 3.6.25.","date":"2023-06-22"},{"id":"bef87735008214d2867c6c6a4c74b80b75def2e0","name":"Ninja Forms <= 3.6.24 - Authenticated (Admin+) Arbitrary File Deletion","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ninja-forms\/ninja-forms-3624-authenticated-admin-arbitrary-file-deletion","description":"The Ninja Forms plugin for WordPress is vulnerable to arbitrary file deletions in versions up to, and including, 3.6.24. This is due to insufficient restriction on the file path that can be supplied during file deletion. This makes it possible for authenticated attackers, with administrative-level access, to delete arbitrary files on the server. One such file that could be targeted is wp-config.php which if deleted can make it possible for an attacker to connect a site to their own database and ultimately achieve remote code execution on the server.","date":"2023-06-22"},{"id":"7106f09f-be12-4ecb-8e1b-71662b8b1318","name":"Ninja Forms &lt; 3.6.25 - Admin+ Arbitrary File Deletion","link":"https:\/\/wpscan.com\/vulnerability\/7106f09f-be12-4ecb-8e1b-71662b8b1318","description":"The plugin does not validate the path of files to be deleted, which could allow administrators to delete arbitrary files on the server even when they should not be able to.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:C\/C:N\/I:N\/A:H","av":"n","ac":"l","pr":"h","ui":"n","s":"c","c":"n","i":"n","a":"h","score":"6.8","severity":"m","exploitable":"1.2","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:C\/C:N\/I:N\/A:H","score":"6.8","severity":"medium","av":"network","ac":"low","pr":"high","ui":"none","s":"changed","c":"none","i":"none","a":"high","exploitable":"1.2","impact":"5.9"},"cwe":[{"cwe":"CWE-20","name":"Improper Input Validation","description":"The product receives input or data, but it does\n        not validate or incorrectly validates that the input has the\n        properties that are required to process the data safely and\n        correctly."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"d9c81acdcbee1861300c633814d633771ff01f50fe06a0634fe89d7715caefb4","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.6.26","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.6.26","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-35909","name":"CVE-2023-35909","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-35909","description":"[en] Uncontrolled Resource Consumption vulnerability in Saturday Drive Ninja Forms Contact Form \u2013 The Drag and Drop Form Builder for WordPress leading to DoS.This issue affects Ninja Forms Contact Form \u2013 The Drag and Drop Form Builder for WordPress: from n\/a through 3.6.25.","date":"2023-12-07"},{"id":"abe456504088e9115b97c4635b4a03d138764284","name":"WordPress  Ninja Forms Plugin  <= 3.6.25 is vulnerable to Denial of Service Attack","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ninja-forms\/vulnerability\/wordpress-ninja-forms-plugin-3-6-25-denial-of-service-attack-vulnerability","description":"Update the WordPress Ninja Forms plugin to the latest available version (at least 3.6.26).\nPetiteMais discovered and reported this Denial of Service Attack vulnerability in WordPress Ninja Forms Plugin. A denial of service attack occurs when a malicious actor can cause the endpoint, or website, to crash or refuse to serve requests to one or more users by causing it to hang, crash or make unusable. This vulnerability has been fixed in version 3.6.26.","date":"2023-07-07"},{"id":"1c97c661c5435e28202b3b6913871f83779fb1a4","name":"Ninja Forms <= 3.6.25 - Denial of Service via Large Form Submissions","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ninja-forms\/ninja-forms-3625-denial-of-service-via-large-form-submissions","description":"The Ninja Forms plugin for WordPress is vulnerable to denial of service in versions up to, and including, 3.6.25. This is due to insufficient controls on form submissions. This makes it possible for unauthenticated attackers to craft form submissions with excessive extra data that may exceed the capacity of the database and prevent further requests from being successful while the submission is processing.","date":"2023-07-07"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:N\/A:L","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"n","i":"n","a":"l","score":"5.3","severity":"m","exploitable":"3.9","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:N\/A:L","score":"5.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"none","i":"none","a":"low","exploitable":"3.9","impact":"1.4"},"cwe":[{"cwe":"CWE-400","name":"Uncontrolled Resource Consumption","description":"The product does not properly control the allocation and maintenance of a limited resource."}]}},{"uuid":"f1e146288b949902ae6545fb25f99e2852278c98607b2ee690948704f9905aab","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.6.26","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.6.26","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-37979","name":"CVE-2023-37979","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-37979","description":"[en] Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Saturday Drive Ninja Forms Contact Form plugin <=\u00a03.6.25 versions.","date":"2023-07-27"},{"id":"7ab9343b81bccbe9ae25f98e8a0d2038397b288b","name":"Ninja Forms <= 3.6.25 - Reflected Cross-Site Scripting via 'data'","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ninja-forms\/ninja-forms-3625-reflected-cross-site-scripting-via-data","description":"The Ninja Forms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the \u2018data\u2019 parameter in versions up to, and including, 3.6.25 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.","date":"2023-07-25"},{"id":"870d094adfda7f6cf62c9dde3bbef967ba5787ef","name":"WordPress  Ninja Forms Plugin  <= 3.6.25 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ninja-forms\/vulnerability\/wordpress-ninja-forms-plugin-3-6-25-reflected-cross-site-scripting-xss-vulnerability","description":"Update the WordPress Ninja Forms plugin to the latest available version (at least 3.6.26).\nRafie Muhammad (Patchstack) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Ninja Forms Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.  This vulnerability has been fixed in version 3.6.26.","date":"2023-07-25"},{"id":"3c7c65e9-c4fd-4d98-ae16-77abffbf7348","name":"Ninja Forms &lt; 3.6.26 - Reflected Cross-Site Scripting","link":"https:\/\/wpscan.com\/vulnerability\/3c7c65e9-c4fd-4d98-ae16-77abffbf7348","description":"The plugin does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:L","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"l","score":"7.1","severity":"h","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:L","score":"7.1","severity":"high","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"low","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"a17967f15e26632db56f27c9fb50e5ef6eb7810c2b10989f4a8423cd5af9ad2b","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.6.26","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.6.26","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-38386","name":"CVE-2023-38386","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-38386","description":"[en] Missing Authorization vulnerability in Saturday Drive Ninja Forms.This issue affects Ninja Forms: from n\/a through 3.6.25.","date":"2024-06-19"},{"id":"c7877dfb0c4b64d84341acd0527876473b43675b","name":"Ninja Forms <= 3.6.25 - Missing Authorization to Contributor+ Form Submission Export","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ninja-forms\/ninja-forms-3625-missing-authorization-to-contributor-form-submission-export","description":"The Ninja Forms plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the export_listen() function in versions up to, and including, 3.6.25. This makes it possible for authenticated attackers, with contributor-level access and above, to export form submissions via a properly crafted request.","date":"2023-07-25"},{"id":"6088776c0e9fecb6794530700320b9e56242eccd","name":"WordPress  Ninja Forms Plugin  <= 3.6.25 is vulnerable to Broken Access Control","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ninja-forms\/vulnerability\/wordpress-ninja-forms-plugin-3-6-25-contributor-broken-access-control-vulnerability","description":"Update the WordPress Ninja Forms plugin to the latest available version (at least 3.6.26).\nRafie Muhammad (Patchstack) discovered and reported this Broken Access Control vulnerability in WordPress Ninja Forms Plugin.  This vulnerability has been fixed in version 3.6.26.","date":"2023-07-25"},{"id":"92c13556-4fe9-41f8-84c5-0f218a1bc73d","name":"Ninja Forms &lt; 3.6.26 - Contributor+ Form Entries Export","link":"https:\/\/wpscan.com\/vulnerability\/92c13556-4fe9-41f8-84c5-0f218a1bc73d","description":"The plugin does not have proper authorisation check in the export_listen function, which could allow Contributors and above roles to export and download submitted form entries","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:L\/A:L","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"h","i":"l","a":"l","score":"7.6","severity":"h","exploitable":"3.9","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:L\/A:L","score":"7.6","severity":"high","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"high","i":"low","a":"low","exploitable":"3.9","impact":"5.9"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"18f5a9a30bbfdc656415aa6fcc8fd52b159e725bb57f1dcf0f4ad57b382497ff","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.6.26","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.6.26","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-38393","name":"CVE-2023-38393","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-38393","description":"[en] Missing Authorization vulnerability in Saturday Drive Ninja Forms.This issue affects Ninja Forms: from n\/a through 3.6.25.","date":"2024-06-19"},{"id":"9cca2d09e979392b0883e51dd42d8b9a0a6f1b62","name":"Ninja Forms <= 3.6.25 - Missing Authorization to Form Submission Export","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ninja-forms\/ninja-forms-3625-missing-authorization-to-form-submission-export","description":"The Ninja Forms plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the processing() function in versions up to, and including, 3.6.25. This makes it possible for authenticated attackers, with subscriber-level access and above, to export form submissions via the nf_download_all_subs AJAX action.","date":"2023-07-25"},{"id":"131a7954c1a2e69bddaefd4db95e2111c587d3a2","name":"WordPress  Ninja Forms Plugin  <= 3.6.25 is vulnerable to Broken Access Control","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ninja-forms\/vulnerability\/wordpress-ninja-forms-plugin-3-6-25-subscriber-broken-access-control-vulnerability","description":"Update the WordPress Ninja Forms plugin to the latest available version (at least 3.6.26).\nRafie Muhammad (Patchstack) discovered and reported this Broken Access Control vulnerability in WordPress Ninja Forms Plugin.  This vulnerability has been fixed in version 3.6.26.","date":"2023-07-25"},{"id":"81998700-78f5-4e4d-9186-2ed1433dee0a","name":"Ninja Forms &lt; 3.6.26 - Subscriber+ Form Entries Export","link":"https:\/\/wpscan.com\/vulnerability\/81998700-78f5-4e4d-9186-2ed1433dee0a","description":"The plugin does not have proper authorisation check in the processing function, which could allow any authenticated users, such as subscriber to export and download submitted form entries","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:L\/A:L","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"h","i":"l","a":"l","score":"7.6","severity":"h","exploitable":"2.8","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:L\/A:L","score":"7.6","severity":"high","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"high","i":"low","a":"low","exploitable":"2.8","impact":"5.9"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"poc","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"19c475280fe0407cf8355984a5b5ffcaab8c47d1bd21d7bfc7e7a80f6e9ff46e","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.6.11","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.6.11","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"8843d66b-e895-4336-afda-00b99442cdc1","name":"Ninja Forms &lt; 3.6.11 - Unauthenticated PHP Object Injection","link":"https:\/\/wpscan.com\/vulnerability\/8843d66b-e895-4336-afda-00b99442cdc1","description":"The plugin does not validate merge tags provided in the request, which could allow unauthenticated attackers to call any static method present in the blog. One from the plugin in particular could allow for PHP Object Injection when a suitable gadget is also present on the blog. Attackers have been exploiting such issue since June 9th, 2022","date":null}],"impact":[]},{"uuid":"5b943d258f1d2a66374f8edd5ee84b0652dfaacc57b461f0b9e24d945d1fdf24","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.6.8","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.6.8","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"cec7d366-7663-4b83-9640-a58f2fcf5e41","name":"Ninja Forms &lt; 3.6.8 - Unauthenticated Email Address Disclosure","link":"https:\/\/wpscan.com\/vulnerability\/cec7d366-7663-4b83-9640-a58f2fcf5e41","description":"The plugin does not delete the temporary files created when exporting submissions, which could allow unauthenticated attackers to download them and get sensitive information such as the email address of users who submitted a form given that the file is publicly accessible, and with a guessable name","date":null}],"impact":[]},{"uuid":"e7497c44d49b0db5af529e3c8a84f64a57eff38302b7d9f8486c376dc8e2a405","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.5.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.5.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"ba6fa3d6-e3f7-449a-bd78-d57c26a67aa6","name":"Nina Forms &lt; 3.5.5 - Reflected Cross-Site Scripting","link":"https:\/\/wpscan.com\/vulnerability\/ba6fa3d6-e3f7-449a-bd78-d57c26a67aa6","description":"The plugin does not escape generated links before outputting them in attributes, leading to Reflected Cross-Site Scripting","date":null}],"impact":[]},{"uuid":"74cacc1056c6ca51b669b0b8ff27342585adab9d9f2574510e2068e43cac0967","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.3.21.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.3.21.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"730abdcf-e0a0-4d7c-a3b6-ca56c6a59df2","name":"Ninja Forms &lt;= 3.3.21 - XSS and SQLi","link":"https:\/\/wpscan.com\/vulnerability\/730abdcf-e0a0-4d7c-a3b6-ca56c6a59df2","description":"Reflected XSS vulnerability in the administrative dashboard.\r\n\r\nBlind SQL injection vulnerability in the search filter on the submissions page.","date":null}],"impact":[]},{"uuid":"037a25849c6a612450f71691d7eb33d86017dbf6877622679c294ad88fce8f1e","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.3.14","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.3.14","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"fd19ade3-4d3b-446e-9b08-7b07b1ec1927","name":"Ninja Forms &lt;= 3.3.13 - Cross-Site Scripting (XSS) in Import Function","link":"https:\/\/wpscan.com\/vulnerability\/fd19ade3-4d3b-446e-9b08-7b07b1ec1927","description":"The Ninja Forms Contact Form &ndash; The Drag and Drop Form Builder for WordPress WordPress plugin was affected by a Cross-Site Scripting (XSS) in Import Function security vulnerability.","date":null}],"impact":[]},{"uuid":"79f839f88ef4631a346ef20962761d4c18936d7a3be0108468444bd016588dde","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 2.9.55.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.9.55.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"a494753c-187e-4de9-9564-dc8a36df048b","name":"Ninja Forms &lt;= 2.9.55.1 - Authenticated SQL Injection","link":"https:\/\/wpscan.com\/vulnerability\/a494753c-187e-4de9-9564-dc8a36df048b","description":"The Ninja Forms Contact Form &ndash; The Drag and Drop Form Builder for WordPress WordPress plugin was affected by an Authenticated SQL Injection security vulnerability.","date":null}],"impact":[]},{"uuid":"3ec6e059dc2d9056fdd13de36cc13039ae7655f4b01dadfdf1b0b8faf2a40c2c","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 2.9.52","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.9.52","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"a495b360-a81f-4d42-a8d4-a74e2c2a7cee","name":"Ninja Forms &lt;= 2.9.51 - Multiple Authenticated Cross-Site Scripting (XSS)","link":"https:\/\/wpscan.com\/vulnerability\/a495b360-a81f-4d42-a8d4-a74e2c2a7cee","description":"The Ninja Forms Contact Form &ndash; The Drag and Drop Form Builder for WordPress WordPress plugin was affected by a Multiple Authenticated Cross-Site Scripting (XSS) security vulnerability.","date":null}],"impact":[]},{"uuid":"914e0c0071ee05e21f3d964e0431ab91e20c9247449086b6069ada85b7fd8a35","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 2.9.28","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.9.28","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"a3146860-4065-437b-8a17-7a8ac802c565","name":"Ninja Forms &lt;= 2.9.27 - Malicious File Export","link":"https:\/\/wpscan.com\/vulnerability\/a3146860-4065-437b-8a17-7a8ac802c565","description":"The Ninja Forms Contact Form &ndash; The Drag and Drop Form Builder for WordPress WordPress plugin was affected by a Malicious File Export  security vulnerability.","date":null}],"impact":[]},{"uuid":"c8b4ed7327efb604e63f9dfa63a63aa379d0cca16e8bd8ebc31517e8cb9148fe","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 2.9.22","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.9.22","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"c84fa906-4d70-4d4d-990e-a0510bcf72ed","name":"Ninja Forms &lt;= 2.9.21 - Authenticated Reflected Cross-Site Scripting (XSS)","link":"https:\/\/wpscan.com\/vulnerability\/c84fa906-4d70-4d4d-990e-a0510bcf72ed","description":"The Ninja Forms Contact Form &ndash; The Drag and Drop Form Builder for WordPress WordPress plugin was affected by an Authenticated Reflected Cross-Site Scripting (XSS) security vulnerability.","date":null}],"impact":[]},{"uuid":"4e3ef57105d7129fc5c4f05fc50039dba91dcbdc3c00277d78d50d0ebf146b1c","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 2.9.19","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.9.19","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"0dc1757f-dbe1-454f-a476-0305aee23fb6","name":"Ninja Forms &lt;= 2.9.18 - Cross-Site Scripting (XSS)","link":"https:\/\/wpscan.com\/vulnerability\/0dc1757f-dbe1-454f-a476-0305aee23fb6","description":"The Ninja Forms Contact Form &ndash; The Drag and Drop Form Builder for WordPress WordPress plugin was affected by a Cross-Site Scripting (XSS) security vulnerability.","date":null}],"impact":[]},{"uuid":"19656851d6feb7fd6631785a51f2666781b041df3fec8b93f3cd071496f4c786","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 2.9.11","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.9.11","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"d0adf831-26c0-46f8-8964-df5f48ec77cd","name":"Ninja Forms &lt;= 2.9.10 - Cross-Site Scripting (XSS)","link":"https:\/\/wpscan.com\/vulnerability\/d0adf831-26c0-46f8-8964-df5f48ec77cd","description":"The Ninja Forms Contact Form &ndash; The Drag and Drop Form Builder for WordPress WordPress plugin was affected by a Cross-Site Scripting (XSS) security vulnerability.","date":null}],"impact":[]},{"uuid":"b2fe108d1353097e716f2b715b2ddb2b26b4504eef5b28fa3f9900df90e4b82b","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.6.26","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.6.26","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-4109","name":"CVE-2023-4109","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-4109","description":"[en] The Ninja Forms WordPress Ninja Forms Contact Form WordPress plugin before 3.6.26 was affected by a HTML Injection security vulnerability.","date":"2023-08-30"},{"id":"bbc22d1b72373d9b0bbf4fd42b96c515392a8222","name":"Ninja Forms <= 3.6.25 - Authenticated (Administrator+) Stored HTML Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ninja-forms\/ninja-forms-3625-authenticated-administrator-stored-html-injection","description":"The Ninja Forms plugin for WordPress is vulnerable to Stored HTML Injection in versions up to, and including, 3.6.25 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrator access to inject arbitrary HTML content in pages that will execute whenever a user accesses an injected page.","date":"2023-08-07"},{"id":"558e06ab-704b-4bb1-ba7f-b5f6bbbd68d9","name":"Ninja Forms &lt; 3.6.26 - Admin+ Stored HTML Injection","link":"https:\/\/wpscan.com\/vulnerability\/558e06ab-704b-4bb1-ba7f-b5f6bbbd68d9","description":"The Ninja Forms WordPress plugin was affected by a HTML Injection security vulnerability.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"h","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"4.8","severity":"m","exploitable":"1.7","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"4.8","severity":"medium","av":"network","ac":"low","pr":"high","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"1.7","impact":"2.7"},"cwe":[{"cwe":"CWE-80","name":"Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)","description":"The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special characters such as \"<\", \">\", and \"&\" that could be interpreted as web-scripting elements when they are sent to a downstream component that processes web pages."}],"ssvc":{"exploitation":"poc","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"91507e6fad838aba73f50d3d8014b982dd38adfd07a3a051536bbb021c4fcb10","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.6.34","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.6.34","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-5530","name":"CVE-2023-5530","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-5530","description":"[en] The Ninja Forms Contact Form WordPress plugin before 3.6.34 does not sanitize and escape its label fields, which could allow high privilege users such as admin to perform Stored XSS attacks. Only users with the unfiltered_html capability can perform this, and such users are already allowed to use JS in posts\/comments etc however the vendor acknowledged and fixed the issue","date":"2023-11-06"},{"id":"14f7271cc9a0b1c66a32e8abe1ed3b2bf5ec4c2c","name":"Ninja Forms Contact Form <= 3.6.33 - Authenticated (Admin+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/UNKNOWN-CVE-2023-5530-1\/ninja-forms-contact-form-3633-authenticated-admin-stored-cross-site-scripting","description":"The Ninja Forms Contact Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.6.33 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.","date":"2023-10-16"},{"id":"15689c879e835ecc7f2b3b44e7a01092fc00d196","name":"WordPress  Ninja Forms Plugin  < 3.6.34 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ninja-forms\/vulnerability\/wordpress-ninja-forms-plugin-3-6-34-admin-stored-xss-vulnerability","description":"Update the WordPress Ninja Forms plugin to the latest available version (at least 3.6.34).\nJonathan Zamora discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Ninja Forms Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.  This vulnerability has been fixed in version 3.6.34.","date":"2023-11-07"},{"id":"a642f313-cc3e-4d75-b207-1dceb6a7fbae","name":"Ninja Forms &lt; 3.6.34 - Admin+ Stored XSS","link":"https:\/\/wpscan.com\/vulnerability\/a642f313-cc3e-4d75-b207-1dceb6a7fbae","description":"The plugin does not sanitize and escape its label fields, which could allow high privilege users such as admin to perform Stored XSS attacks. Only users with the unfiltered_html capability can perform this, and such users are already allowed to use JS in posts\/comments etc however the vendor acknowledged and fixed the issue","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"h","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"4.8","severity":"m","exploitable":"1.7","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"4.8","severity":"medium","av":"network","ac":"low","pr":"high","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"1.7","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"e0c3990c463e2d2fc95644d84262e56367a4d845bf6486c23fdd92c1ac9434e7","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.7.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.7.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-0685","name":"CVE-2024-0685","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-0685","description":"[en] The Ninja Forms Contact Form \u2013 The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Second Order SQL Injection via the email address value submitted through forms in all versions up to, and including, 3.7.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for unauthenticated attackers to inject SQL in their email address that will append additional into the already existing query when an administrator triggers a personal data export.","date":"2024-02-02"},{"id":"6ed8517ba38f28359d7e37e2e6e4246bc4322b62","name":"Ninja Forms Contact Form <= 3.7.1 - Unauthenticated Second Order SQL Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ninja-forms\/ninja-forms-contact-form-371-unauthenticated-second-order-sql-injection","description":"The Ninja Forms Contact Form \u2013 The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Second Order SQL Injection via the email address value submitted through forms in all versions up to, and including, 3.7.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for unauthenticated attackers to inject SQL in their email address that will append additional into the already existing query when an administrator triggers a personal data export.","date":"2024-02-01"},{"id":"6d630a7a727c80b050de11f6efbadaa7bb2cb114","name":"WordPress  Ninja Forms Plugin  <= 3.7.1 is vulnerable to SQL Injection","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ninja-forms\/vulnerability\/wordpress-ninja-forms-contact-form-plugin-3-7-1-unauthenticated-second-order-sql-injection-vulnerability","description":"Update the WordPress Ninja Forms File Uploads Extension plugin to the latest available version (at least 3.7.2).\nstealthcopter discovered and reported this SQL Injection vulnerability in WordPress Ninja Forms Plugin. This could allow a malicious actor to directly interact with your database, including but not limited to stealing information. This vulnerability has been fixed in version 3.7.2.\nHave additional information or questions about this entry? Get in touch.","date":null},{"id":"8e5c6259-f7d6-474d-932b-a5d186b94c2a","name":"Ninja Forms Contact Form &lt; 3.7.2 - Unauthenticated Second Order SQL Injection","link":"https:\/\/wpscan.com\/vulnerability\/8e5c6259-f7d6-474d-932b-a5d186b94c2a","description":"The plugin is vulnerable to Second Order SQL Injection via the email address value submitted through forms due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for unauthenticated attackers to inject SQL in their email address that will append additional into the already existing query when an administrator triggers a personal data export.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"9.8","severity":"c","exploitable":"3.9","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"9.8","severity":"critical","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"3.9","impact":"5.9"},"cwe":[{"cwe":"CWE-89","name":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')","description":"The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"caa8f31741c651027dcd0142f800713707a143738c82d8a327ddbe196772a031","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.8.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.8.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-2108","name":"CVE-2024-2108","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-2108","description":"[en] The Ninja Forms Contact Form \u2013 The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an image title embedded into a form in all versions up to, and including, 3.8.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-03-29"},{"id":"7589e44c99b15dc47bb143ed84310aa5b98cb741","name":"Ninja Forms Contact Form \u2013 The Drag and Drop Form Builder for WordPress <= 3.8.0 - Authenticated (Author+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ninja-forms\/ninja-forms-contact-form-the-drag-and-drop-form-builder-for-wordpress-380-authenticated-author-stored-cross-site-scripting","description":"The Ninja Forms Contact Form \u2013 The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an image title embedded into a form in all versions up to, and including, 3.8.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-03-28"},{"id":"c9f2cd2a6c910cc174ab97c321ec55f60640654a","name":"WordPress  Ninja Forms Plugin    <= 3.8.0 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ninja-forms\/vulnerability\/wordpress-ninja-forms-contact-form-the-drag-and-drop-form-builder-for-wordpress-plugin-3-8-0-authenticated-author-stored-cross-site-scripting-vulnerability","description":"Update the WordPress Ninja Forms plugin to the latest available version (at least 3.8.1).\nTim Coen discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Ninja Forms Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.  This vulnerability has been fixed in version 3.8.1.\nHave additional information or questions about this entry? Get in touch.","date":null},{"id":"c89ce032-c361-49e2-8ed0-c806bf399d96","name":"Ninja Forms Contact Form &lt; 3.8.1 - Author+ Stored XSS","link":"https:\/\/wpscan.com\/vulnerability\/c89ce032-c361-49e2-8ed0-c806bf399d96","description":"The plugin is vulnerable to Stored Cross-Site Scripting via an image title embedded into a form due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"365927611b2f37443c75aa62b72231df55c9dcc06107a917241748029fe5b973","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.8.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.8.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-2113","name":"CVE-2024-2113","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-2113","description":"[en] The Ninja Forms Contact Form \u2013 The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.8.0. This is due to missing or incorrect nonce validation on the nf_download_all_subs AJAX action. This makes it possible for unauthenticated attackers to trigger an export of a form's submission to a publicly accessible location via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":"2024-03-29"},{"id":"efae5b7837ea5e7fd483e760c8fd1505e5e63608","name":"Ninja Forms Contact Form \u2013 The Drag and Drop Form Builder for WordPress <= 3.8.0 - Cross-Site Request Forgery to Publicly Accessible Form Submission Export","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ninja-forms\/ninja-forms-contact-form-the-drag-and-drop-form-builder-for-wordpress-380-cross-site-request-forgery-to-publicly-accessible-form-submission-export","description":"The Ninja Forms Contact Form \u2013 The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.8.0. This is due to missing or incorrect nonce validation on the nf_download_all_subs AJAX action. This makes it possible for unauthenticated attackers to trigger an export of a form's submission to a publicly accessible location via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":"2024-03-28"},{"id":"1ca36d05a838aa1117a057d977aee1c853b82ab4","name":"WordPress  Ninja Forms Plugin    <= 3.8.0 is vulnerable to Cross Site Request Forgery (CSRF)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ninja-forms\/vulnerability\/wordpress-ninja-forms-contact-form-the-drag-and-drop-form-builder-for-wordpress-plugin-3-8-0-cross-site-request-forgery-to-publicly-accessible-form-submission-export-vulnerability","description":"Update the WordPress Ninja Forms plugin to the latest available version (at least 3.8.1).\nTobias Wei\u00dfhaar (kun_19) discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress Ninja Forms Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted actions under their current authentication. This vulnerability has been fixed in version 3.8.1.\nHave additional information or questions about this entry? Get in touch.","date":null},{"id":"9107e702-e5ef-4328-8265-2a6b98092b3a","name":"Ninja Forms Contact Form &lt; 3.8.1 - Publicly Accessible Form Submission Export via CSRF","link":"https:\/\/wpscan.com\/vulnerability\/9107e702-e5ef-4328-8265-2a6b98092b3a","description":"The plugin is vulnerable to Cross-Site Request Forgery This is due to missing or incorrect nonce validation on the nf_download_all_subs AJAX action. This makes it possible for unauthenticated attackers to trigger an export of a form&#039;s submission to a publicly accessible location via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:L\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"u","c":"l","i":"n","a":"n","score":"4.3","severity":"m","exploitable":"2.8","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:L\/I:N\/A:N","score":"4.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"unchanged","c":"low","i":"none","a":"none","exploitable":"2.8","impact":"1.4"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."},{"cwe":"CWE-352","name":"Cross-Site Request Forgery (CSRF)","description":"The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"a13d8cbd1ba5d91a19deff8b5b3397c859408a4748c427909078532bac8191d5","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.8.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.8.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-29220","name":"CVE-2024-29220","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-29220","description":"[en] Ninja Forms prior to 3.8.1 contains a cross-site scripting vulnerability in custom fields for labels. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who is accessing to the website using the product.","date":"2024-04-11"},{"id":"e04a03156bb6d70ce0ddcc20b7529d6397834727","name":"Ninja Forms \u2013 The Contact Form Builder That Grows With You <= 3.8.0 - Authenticated (Admin+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ninja-forms\/ninja-forms-the-contact-form-builder-that-grows-with-you-380-authenticated-admin-stored-cross-site-scripting-1","description":"The Ninja Forms \u2013 The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a form field in all versions up to, and including, 3.8.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.","date":"2024-04-08"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"b4bbfd391fade51db826e3d52f5a1f8050f96052694d71aed1b86e5570bb4c62","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.8.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.8.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-26019","name":"CVE-2024-26019","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-26019","description":"[en] Ninja Forms prior to 3.8.1 contains a cross-site scripting vulnerability in submit processing. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who is accessing to the website using the product.","date":"2024-04-11"},{"id":"4600f789f71ea3554b41e1e454f007afbef4eec6","name":"Ninja Forms \u2013 The Contact Form Builder That Grows With You <= 3.8.0 - Authenticated (Admin+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ninja-forms\/ninja-forms-the-contact-form-builder-that-grows-with-you-380-authenticated-admin-stored-cross-site-scripting","description":"The Ninja Forms \u2013 The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form fields in all versions up to, and including, 3.8.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.","date":"2024-04-08"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"3e3822b2fa242e394e39a885b8873a01a3499e9ac9c1e993504ffd4903d58a3a","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.8.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.8.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-25572","name":"CVE-2024-25572","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-25572","description":"[en] Cross-site request forgery (CSRF) vulnerability exists in Ninja Forms prior to 3.4.31. If a website administrator views a malicious page while logging in, unintended operations may be performed.","date":"2024-04-11"},{"id":"JVNDB-2024-000038","name":"Multiple vulnerabilities in WordPress Plugin \"Ninja Forms\"","link":"http:\/\/jvndb.jvn.jp\/jvndb\/JVNDB-2024-000038","description":"WordPress Plugin \"Ninja Forms\" provided by Saturday Drive contains multiple vulnerabilities listed below.  * Cross-site request forgery (CWE-352) - CVE-2024-25572 * Stored cross-site scripting in submit processing (CWE-79) - CVE-2024-26019 * Stored cross-site scripting in custom fields for labels (CWE-79) - CVE-2024-29220  CVE-2024-25572 Kohei Agena reported this vulnerability to IPA. JPCERT\/CC coordinated with the developer under Information Security Early Warning Partnership.  CVE-2024-26019, CVE-2024-29220 Ryotaro Imamura of SB Technology Corp. reported these vulnerabilities to IPA. JPCERT\/CC coordinated with the developer under Information Security Early Warning Partnership.","date":"2024-04-08"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"n","ui":"r","s":"u","c":"h","i":"h","a":"h","score":"8.8","severity":"h","exploitable":"2.8","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:H\/I:H\/A:H","score":"8.8","severity":"high","av":"network","ac":"low","pr":"none","ui":"required","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"2.8","impact":"5.9"},"cwe":[{"cwe":"CWE-352","name":"Cross-Site Request Forgery (CSRF)","description":"The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"c2feec4599152954b40b0db1ca2bf16d55293a223bd93be4d18a7949f77a8b1e","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.8.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.8.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-37934","name":"CVE-2024-37934","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-37934","description":"[en] Improper Control of Generation of Code ('Code Injection') vulnerability in Saturday Drive Ninja Forms allows Code Injection.This issue affects Ninja Forms: from n\/a through 3.8.4.","date":"2024-07-09"},{"id":"fae4f13cd2f06b4e678cbb273c087d752fbc6a24","name":"WordPress Ninja Forms Plugin <= 3.8.4 is vulnerable to Broken Access Control","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ninja-forms\/vulnerability\/wordpress-ninja-forms-plugin-3-8-4-subscriber-arbitrary-shortcode-execution-vulnerability","description":"<p>WordPress Ninja Forms Plugin <= 3.8.4 is vulnerable to Broken Access Control<\/p><p>Software: Ninja Forms<\/p><p>Link: https:\/\/wordpress.org\/plugins\/ninja-forms\/#developers<\/p><p>Affected Version <= 3.8.4<\/p><p>Fixed in version 3.8.5 <\/p>","date":"2024-07-04"},{"id":"3f3e1404ac67bd31049df4337217ab2290b9608f","name":"Ninja Forms <= 3.8.4 - Authenticated (Subscriber+) Arbitrary Shortcode Execution","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ninja-forms\/ninja-forms-384-authenticated-subscriber-arbitrary-shortcode-execution","description":"The The Ninja Forms \u2013 The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.8.4. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for authenticated attackers, with subscriber-level access and above, to execute arbitrary shortcodes.","date":"2024-07-04"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"9.8","severity":"c","exploitable":"3.9","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"9.8","severity":"critical","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"3.9","impact":"5.9"},"cwe":[{"cwe":"CWE-94","name":"Improper Control of Generation of Code ('Code Injection')","description":"The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"7485ce6dbc991c8c7331811c66ab67a416c435726354754cf24f3e9101c2650e","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.8.7","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.8.7","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-39628","name":"CVE-2024-39628","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-39628","description":"[en] Cross-Site Request Forgery (CSRF) vulnerability in Saturday Drive Ninja Forms allows Cross Site Request Forgery.This issue affects Ninja Forms: from n\/a through 3.8.6.","date":"2024-08-26"},{"id":"de2e6de0ae3081760d75ebb2411c2bb1094696d8","name":"WordPress Ninja Forms Plugin <= 3.8.6 is vulnerable to Cross Site Request Forgery (CSRF)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ninja-forms\/vulnerability\/wordpress-ninja-forms-plugin-3-8-6-cross-site-request-forgery-csrf-vulnerability","description":"<p>WordPress Ninja Forms Plugin <= 3.8.6 is vulnerable to Cross Site Request Forgery (CSRF)<\/p><p>Software: Ninja Forms<\/p><p>Link: https:\/\/wordpress.org\/plugins\/ninja-forms\/#developers<\/p><p>Affected Version <= 3.8.6<\/p><p>Fixed in version 3.8.7 <\/p>","date":"2024-07-24"},{"id":"9ee6af622d86035308a7919642fd812c73be1079","name":"Ninja Forms <= 3.8.6 - Cross-Site Request Forgery","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ninja-forms\/ninja-forms-386-cross-site-request-forgery","description":"The Ninja Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.8.6. This is due to missing or incorrect nonce validation on the submit_listener() function. This makes it possible for unauthenticated attackers to update license details via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":"2024-07-24"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"n","ui":"r","s":"u","c":"h","i":"h","a":"h","score":"8.8","severity":"h","exploitable":"2.8","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:H\/I:H\/A:H","score":"8.8","severity":"high","av":"network","ac":"low","pr":"none","ui":"required","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"2.8","impact":"5.9"},"cwe":[{"cwe":"CWE-352","name":"Cross-Site Request Forgery (CSRF)","description":"The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"6edb7709ef0f5d5ff1b90ca25c8e9779887a7ab3ee64849d44fab2b7d9738f13","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.8.12","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.8.12","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-43999","name":"CVE-2024-43999","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-43999","description":"[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Saturday Drive Ninja Forms allows Stored XSS.This issue affects Ninja Forms: from n\/a through 3.8.11.","date":"2024-09-17"},{"id":"07336d82af4a73daa86b35282fe346a58f657ae9","name":"WordPress Ninja Forms Plugin <= 3.8.11 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ninja-forms\/vulnerability\/wordpress-ninja-forms-plugin-3-8-11-cross-site-scripting-xss-vulnerability","description":"<p>WordPress Ninja Forms Plugin <= 3.8.11 is vulnerable to Cross Site Scripting (XSS)<\/p><p>Software: Ninja Forms<\/p><p>Link: https:\/\/wordpress.org\/plugins\/ninja-forms\/#developers<\/p><p>Affected Version <= 3.8.11<\/p><p>Fixed in version 3.8.12 <\/p>","date":"2024-08-28"},{"id":"e6f55372093aec5afe9ab66ca388a85301f2aba3","name":"Ninja Forms <= 3.8.11 - Authenticated (Administrator+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ninja-forms\/ninja-forms-3811-authenticated-administrator-stored-cross-site-scripting","description":"The Ninja Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.8.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only impacts multi-site installations and installations where unfiltered_html has been disabled.","date":"2024-08-28"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"h","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"4.8","severity":"m","exploitable":"1.7","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"4.8","severity":"medium","av":"network","ac":"low","pr":"high","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"1.7","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"7543704e00684d07d231fbeb50af7d7603f255249e338094baec4e08d6e9b50e","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.8.11","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.8.11","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-7354","name":"CVE-2024-7354","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-7354","description":"[en] The Ninja Forms  WordPress plugin before 3.8.11 does not escape an URL before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin","date":"2024-09-02"},{"id":"f806e740f4d28763411802ac5f8a56a8571cfd76","name":"Ninja Forms \u2013 The Contact Form Builder That Grows With You <= 3.8.10 - Reflected Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ninja-forms\/ninja-forms-the-contact-form-builder-that-grows-with-you-3810-reflected-cross-site-scripting","description":"The Ninja Forms \u2013 The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in versions 3.8.6 to 3.8.10. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.","date":"2024-08-12"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"poc","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"6451fb954ecf6f5b8ba7550aaf0b28544d4b2188852aa6f1eab6c75dbd379e62","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] >= 3.8.6 - <= 3.8.10","description":null,"operator":{"min_version":"3.8.6","min_operator":"ge","max_version":"3.8.10","max_operator":"le","unfixed":"0","closed":"0"},"source":[{"id":"de4537020d7c9e36885cc1b5b28145cc99523699","name":"WordPress Ninja Forms Plugin 3.8.6-3.8.10 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ninja-forms\/vulnerability\/wordpress-ninja-forms-plugin-3-8-6-3-8-10-reflected-xss","description":"<p>WordPress Ninja Forms Plugin 3.8.6-3.8.10 is vulnerable to Cross Site Scripting (XSS)<\/p><p>Software: Ninja Forms<\/p><p>Link: https:\/\/wordpress.org\/plugins\/ninja-forms\/#developers<\/p><p>Affected Version 3.8.6-3.8.10<\/p><p>Fixed in version 3.8.11 <\/p>","date":"2024-09-03"}],"impact":[]},{"uuid":"08b6f6b2c10218eb5952e463240de94a03780937793907f1f54eab8d804e98ab","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.8.16","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.8.16","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-3866","name":"CVE-2024-3866","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-3866","description":"[en] The Ninja Forms Contact Form plugin for WordPress is vulnerable to Reflected Self-Based Cross-Site Scripting via the 'Referer' header in all versions up to, and including, 3.8.15 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. Successful exploitation of this vulnerability requires \"maintenance mode\" for a targeted form to be enabled. However, there is no setting available to the attacker or even an administrator-level user to enable this mode. The mode is only enabled during a required update, which is a very short window of time. Additionally, because of the self-based nature of this vulnerability, attackers would have to rely on additional techniques to execute a supplied payload in the context of targeted user.","date":"2024-09-25"},{"id":"df8fa0fc95cd26fa5e694181fd083516493955fd","name":"WordPress Ninja Forms Plugin <= 3.8.15 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ninja-forms\/vulnerability\/wordpress-ninja-forms-contact-form-plugin-3-8-15-reflected-self-based-cross-site-scripting-via-referer-vulnerability","description":"<p>WordPress Ninja Forms Plugin <= 3.8.15 is vulnerable to Cross Site Scripting (XSS)<\/p><p>Software: Ninja Forms<\/p><p>Link: https:\/\/wordpress.org\/plugins\/ninja-forms\/#developers<\/p><p>Affected Version <= 3.8.15<\/p><p>Fixed in version 3.8.16 <\/p>","date":"2024-09-25"},{"id":"c983965ea1f2c0401ab28b12a1911eead99fbf72","name":"Ninja Forms Contact Form <= 3.8.15 - Reflected Self-Based Cross-Site Scripting via Referer","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ninja-forms\/ninja-forms-contact-form-3815-reflected-self-based-cross-site-scripting-via-referer","description":"The Ninja Forms Contact Form plugin for WordPress is vulnerable to Reflected Self-Based Cross-Site Scripting via the 'Referer' header in all versions up to, and including, 3.8.15 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. Successful exploitation of this vulnerability requires \"maintenance mode\" for a targeted form to be enabled. However, there is no setting available to the attacker or even an administrator-level user to enable this mode. The mode is only enabled during a required update, which is a very short window of time. Additionally, because of the self-based nature of this vulnerability, attackers would have to rely on additional techniques to execute a supplied payload in the context of targeted user.","date":"2024-09-24"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"f34313b1bde85f772726689290c7c1d1b1512235b6cb7c0668d9ab7d0011f21d","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.8.18","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.8.18","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-50514","name":"CVE-2024-50514","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-50514","description":"[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kevin Stover Ninja Forms ninja-forms allows Stored XSS.This issue affects Ninja Forms: from n\/a through <= 3.8.16.","date":"2024-11-19"},{"id":"79b84c93292419999df8b1a9525085361314b36f","name":"WordPress Ninja Forms Plugin <= 3.8.16 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ninja-forms\/vulnerability\/wordpress-ninja-forms-the-contact-form-builder-that-grows-with-you-plugin-3-8-16-cross-site-scripting-xss-vulnerability","description":"<p>WordPress Ninja Forms Plugin <= 3.8.16 is vulnerable to Cross Site Scripting (XSS)<\/p><p>Software: Ninja Forms<\/p><p>Link: https:\/\/wordpress.org\/plugins\/ninja-forms\/#developers<\/p><p>Affected Version <= 3.8.16<\/p><p>Fixed in version 3.8.18 <\/p>","date":"2024-10-28"},{"id":"7c795cbe4b74069796027eabc2f7a6d4d5d1e922","name":"Ninja Forms \u2013 The Contact Form Builder That Grows With You <= 3.8.17 - Authenticated (Admin+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ninja-forms\/ninja-forms-the-contact-form-builder-that-grows-with-you-3816-authenticated-admin-stored-cross-site-scripting","description":"The Ninja Forms \u2013 The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.8.17 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.","date":"2024-10-28"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:L","av":"n","ac":"l","pr":"h","ui":"r","s":"c","c":"l","i":"l","a":"l","score":"5.9","severity":"m","exploitable":"1.7","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:L","score":"5.9","severity":"medium","av":"network","ac":"low","pr":"high","ui":"required","s":"changed","c":"low","i":"low","a":"low","exploitable":"1.7","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"caf090f79d8f0655be86a4ffcc2211d982f46dab9dfed2a9396a6d99f366a185","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.8.18","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.8.18","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-50515","name":"CVE-2024-50515","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-50515","description":"[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kevin Stover Ninja Forms ninja-forms allows Stored XSS.This issue affects Ninja Forms: from n\/a through <= 3.8.16.","date":"2024-11-19"},{"id":"e262ba938cb22c83fd9543d52f8c24416bdbeb1e","name":"WordPress Ninja Forms Plugin <= 3.8.16 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ninja-forms\/vulnerability\/wordpress-ninja-forms-the-contact-form-builder-that-grows-with-you-plugin-3-8-16-cross-site-scripting-xss-vulnerability-2","description":"<p>WordPress Ninja Forms Plugin <= 3.8.16 is vulnerable to Cross Site Scripting (XSS)<\/p><p>Software: Ninja Forms<\/p><p>Link: https:\/\/wordpress.org\/plugins\/ninja-forms\/#developers<\/p><p>Affected Version <= 3.8.16<\/p><p>Fixed in version 3.8.18 <\/p>","date":"2024-10-28"},{"id":"10257f7c2ee8047ec35f5e55dffada9940b82535","name":"Ninja Forms \u2013 The Contact Form Builder That Grows With You <= 3.8.17 - Authenticated (Admin+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ninja-forms\/ninja-forms-the-contact-form-builder-that-grows-with-you-3816-authenticated-admin-stored-cross-site-scripting-1","description":"The Ninja Forms \u2013 The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.8.17 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.","date":"2024-10-28"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:L","av":"n","ac":"l","pr":"h","ui":"r","s":"c","c":"l","i":"l","a":"l","score":"5.9","severity":"m","exploitable":"1.7","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:L","score":"5.9","severity":"medium","av":"network","ac":"low","pr":"high","ui":"required","s":"changed","c":"low","i":"low","a":"low","exploitable":"1.7","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"10a05725886f9d6caddd41af96274dbcd6f6b3d1210d47c77efc60f95a398954","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.8.20","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.8.20","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-11052","name":"CVE-2024-11052","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-11052","description":"[en] The Ninja Forms \u2013 The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the calculations parameter in all versions up to, and including, 3.8.19 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-12-12"},{"id":"547e32d785fc3d9e417b3c5717141c4b741af8d1","name":"Ninja Forms \u2013 The Contact Form Builder That Grows With You <= 3.8.19 - Unauthenticated Stored Cross-Site Scripting via Form Calculations","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ninja-forms\/ninja-forms-the-contact-form-builder-that-grows-with-you-3819-unauthenticated-stored-cross-site-scripting-via-form-calculations","description":"The Ninja Forms \u2013 The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the calculations parameter in all versions up to, and including, 3.8.19 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-12-11"},{"id":"f3a4f26070de24f1d8194431c5924b2c98e71ccc","name":"WordPress Ninja Forms Plugin <= 3.8.19 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ninja-forms\/vulnerability\/wordpress-ninja-forms-plugin-3-8-19-unauthenticated-stored-cross-site-scripting-via-form-calculations-vulnerability","description":"<p>WordPress Ninja Forms Plugin <= 3.8.19 is vulnerable to Cross Site Scripting (XSS)<\/p><p>Software: Ninja Forms<\/p><p>Fixed in version 3.8.20 <\/p><p>Affected Version <= 3.8.19<\/p><p>CVE: CVE-2024-11052<\/p>","date":"2024-12-12"},{"id":"EUVD-2024-34088","name":"EUVD-2024-34088","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2024-34088","description":"The Ninja Forms \u2013 The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the calculations parameter in all versions up to, and including, 3.8.19 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-12-12"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"c","c":"l","i":"l","a":"n","score":"7.2","severity":"h","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:C\/C:L\/I:L\/A:N","score":"7.2","severity":"high","av":"network","ac":"low","pr":"none","ui":"none","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null},"epss":"0.010"}},{"uuid":"8ca21aaf4d1d4d2ffa83cc9e8f986fa3606e217d0f68c5d7f40b763ea2d38025","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.8.23","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.8.23","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-12238","name":"CVE-2024-12238","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-12238","description":"[en] The The Ninja Forms \u2013 The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.8.22. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for authenticated attackers, with Subscriber-level access and above, to execute arbitrary shortcodes.","date":"2024-12-29"},{"id":"ce9e170d938ab63275e3ba5d62b3bb74fca2baaf","name":"Ninja Forms \u2013 The Contact Form Builder That Grows With You <= 3.8.22 - Authenticated (Subscriber+) Arbitrary Shortcode Execution","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ninja-forms\/ninja-forms-the-contact-form-builder-that-grows-with-you-3822-authenticated-subscriber-arbitrary-shortcode-execution","description":"The The Ninja Forms \u2013 The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.8.22. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for authenticated attackers, with Subscriber-level access and above, to execute arbitrary shortcodes.","date":"2024-12-28"},{"id":"EUVD-2024-50705","name":"EUVD-2024-50705","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2024-50705","description":"The The Ninja Forms \u2013 The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.8.22. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for authenticated attackers, with Subscriber-level access and above, to execute arbitrary shortcodes.","date":"2024-12-29"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:L\/I:L\/A:L","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"l","i":"l","a":"l","score":"6.3","severity":"m","exploitable":"2.8","impact":"3.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:L\/I:L\/A:L","score":"6.3","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"low","i":"low","a":"low","exploitable":"2.8","impact":"3.4"},"cwe":[{"cwe":"CWE-94","name":"Improper Control of Generation of Code ('Code Injection')","description":"The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null},"epss":"0.003"}},{"uuid":"c48c17688d254a8ee59ae2d5f27952a1e7c2ea8cd199c24ba40bbb42e6d4b888","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.8.25","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.8.25","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-13470","name":"CVE-2024-13470","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-13470","description":"[en] The Ninja Forms \u2013 The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in all versions up to, and including, 3.8.24 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2025-01-30"},{"id":"929fed41fb5adbec3cfb5ddb032d4bde71263bec","name":"Ninja Forms \u2013 The Contact Form Builder That Grows With You <= 3.8.24 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ninja-forms\/ninja-forms-the-contact-form-builder-that-grows-with-you-3824-authenticated-contributor-stored-cross-site-scripting-via-shortcode","description":"The Ninja Forms \u2013 The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in all versions up to, and including, 3.8.24 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2025-01-29"},{"id":"EUVD-2024-51620","name":"EUVD-2024-51620","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2024-51620","description":"The Ninja Forms \u2013 The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in all versions up to, and including, 3.8.24 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2025-01-30"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"c","c":"l","i":"l","a":"n","score":"6.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","score":"6.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null},"epss":"0.001"}},{"uuid":"55e555d504c169ee5ee818bada420aa66c7a4d6425f1077787abd16bb82e79f1","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.10.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.10.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-2561","name":"Ninja Forms < 3.10.1 - Admin+ Stored XSS","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-2561","description":"The Ninja Forms  WordPress plugin before 3.10.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).","date":"0000-00-00"},{"id":"EUVD-2025-15654","name":"EUVD-2025-15654","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2025-15654","description":"The Ninja Forms  WordPress plugin before 3.10.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).","date":"2025-05-19"},{"id":"7031fe6f087edc5d55b4522518bca859c6f8e35b","name":"Ninja Forms \u2013 The Contact Form Builder That Grows With You <= 3.10.0 - Authenticated (Admin+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ninja-forms\/ninja-forms-the-contact-form-builder-that-grows-with-you-3100-authenticated-admin-stored-cross-site-scripting","description":"The Ninja Forms \u2013 The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.10.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.","date":"2025-04-28"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"h","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"4.8","severity":"m","exploitable":"1.7","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"4.8","severity":"medium","av":"network","ac":"low","pr":"high","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"1.7","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"poc","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"32f19fde966f68da5e2132965e93e996007b091696a22ba43514f0b628a796fe","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.10.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.10.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-2560","name":"Ninja Forms < 3.10.1 - Admin+ Stored XSS","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-2560","description":"The Ninja Forms  WordPress plugin before 3.10.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).","date":"0000-00-00"},{"id":"EUVD-2025-15655","name":"EUVD-2025-15655","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2025-15655","description":"The Ninja Forms  WordPress plugin before 3.10.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).","date":"2025-05-19"},{"id":"ccbacc3b14864e563b2e8554eaf852a62c2f1634","name":"Ninja Forms \u2013 The Contact Form Builder That Grows With You <= 3.10.0 - Authenticated (Admin+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ninja-forms\/ninja-forms-the-contact-form-builder-that-grows-with-you-3100-authenticated-admin-stored-cross-site-scripting-2","description":"The Ninja Forms \u2013 The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.10.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.","date":"2025-04-28"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"h","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"4.8","severity":"m","exploitable":"1.7","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"4.8","severity":"medium","av":"network","ac":"low","pr":"high","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"1.7","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"poc","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"51f42a2a8d1ab946350033100f5cfc73f52808e75e4233ae1f72e7bbe44c99a9","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.10.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.10.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-2524","name":"Ninja Forms < 3.10.1 - Admin+ Stored XSS","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-2524","description":"The Ninja Forms  WordPress plugin before 3.10.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).","date":"0000-00-00"},{"id":"EUVD-2025-15656","name":"EUVD-2025-15656","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2025-15656","description":"The Ninja Forms  WordPress plugin before 3.10.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).","date":"2025-05-19"},{"id":"80788a83d35a56b99e45c23e607076b7af477ba5","name":"Ninja Forms \u2013 The Contact Form Builder That Grows With You <= 3.10.0 - Authenticated (Admin+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ninja-forms\/ninja-forms-the-contact-form-builder-that-grows-with-you-3100-authenticated-admin-stored-cross-site-scripting-1","description":"The Ninja Forms \u2013 The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.10.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.","date":"2025-04-28"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"h","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"4.8","severity":"m","exploitable":"1.7","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"4.8","severity":"medium","av":"network","ac":"low","pr":"high","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"1.7","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"poc","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"956f644f69a4b6bbbd2379c6f0f1cc61f2575bc3cfa27250620e34b126e1b86a","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.10.2.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.10.2.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-5398","name":"Ninja Forms <= 3.10.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via CSTI","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-5398","description":"The Ninja Forms \u2013 The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the use of a templating engine in all versions up to, and including, 3.10.2.1 due to insufficient output escaping on user data passed through the template. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"0000-00-00"},{"id":"42e85af062f50f8f5d3428c8e0c6ca1b2968c074","name":"Ninja Forms <= 3.10.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via CSTI","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ninja-forms\/ninja-forms-31021-authenticated-contributor-stored-cross-site-scripting-via-csti","description":"The Ninja Forms \u2013 The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the use of a templating engine in all versions up to, and including, 3.10.2.1 due to insufficient output escaping on user data passed through the template. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2025-06-26"},{"id":"EUVD-2025-28541","name":"EUVD-2025-28541","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2025-28541","description":"The Ninja Forms \u2013 The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the use of a templating engine in all versions up to, and including, 3.10.2.1 due to insufficient output escaping on user data passed through the template. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2025-06-27"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"fee62dab8df9721299bdc59a28b0d9e651489b13e6987e0482e355584feaa100","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.12.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.12.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-10498","name":"CVE-2025-10498","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-10498","description":"[en] The Ninja Forms \u2013 The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.12.0. This is due to missing or incorrect nonce validation when exporting CSV files. This makes it possible for unauthenticated attackers to delete those files granted they can trick an administrator into performing an action such as clicking on a link.","date":"2025-09-27"},{"id":"EUVD-2025-31402","name":"EUVD-2025-31402","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2025-31402","description":"The Ninja Forms \u2013 The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.12.0. This is due to missing or incorrect nonce validation when exporting CSV files. This makes it possible for unauthenticated attackers to delete those files granted they can trick an administrator into performing an action such as clicking on a link.","date":"2025-09-27"},{"id":"b64ef22845c37eb3584acc8c6e6fb983fa819b7e","name":"Ninja Forms \u2013 The Contact Form Builder That Grows With You <= 3.12.0 - Cross-Site Request Forgery to Limited File Deletion","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ninja-forms\/ninja-forms-the-contact-form-builder-that-grows-with-you-3120-cross-site-request-forgery-to-limited-file-deletion","description":"The Ninja Forms \u2013 The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.12.0. This is due to missing or incorrect nonce validation when exporting CSV files. This makes it possible for unauthenticated attackers to delete those files granted they can trick an administrator into performing an action such as clicking on a link.","date":"2025-09-26"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:L\/A:L","av":"n","ac":"l","pr":"n","ui":"r","s":"u","c":"n","i":"l","a":"l","score":"5.4","severity":"m","exploitable":"2.8","impact":"2.5"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:L\/A:L","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"unchanged","c":"none","i":"low","a":"low","exploitable":"2.8","impact":"2.5"},"cwe":[{"cwe":"CWE-352","name":"Cross-Site Request Forgery (CSRF)","description":"The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"506c78eba9108d74e04daead66e96f53638b2d3b93162bc7efe6cf9d031883af","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.12.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.12.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-10499","name":"CVE-2025-10499","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-10499","description":"[en] The Ninja Forms \u2013 The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.12.0. This is due to missing or incorrect nonce validation on the maybe_opt_in() function. This makes it possible for unauthenticated attackers to opt an affected site into usage statistics collection via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":"2025-09-27"},{"id":"EUVD-2025-31403","name":"EUVD-2025-31403","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2025-31403","description":"The Ninja Forms \u2013 The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.12.0. This is due to missing or incorrect nonce validation on the maybe_opt_in() function. This makes it possible for unauthenticated attackers to opt an affected site into usage statistics collection via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":"2025-09-27"},{"id":"357d67a7055c54e07945a74b13d1b3954f3aba1c","name":"Ninja Forms \u2013 The Contact Form Builder That Grows With You <= 3.12.0 - Cross-Site Request Forgery to Plugin Settings Update","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ninja-forms\/ninja-forms-the-contact-form-builder-that-grows-with-you-3120-cross-site-request-forgery-to-plugin-settings-update","description":"The Ninja Forms \u2013 The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.12.0. This is due to missing or incorrect nonce validation on the maybe_opt_in() function. This makes it possible for unauthenticated attackers to opt an affected site into usage statistics collection via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":"2025-09-26"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"u","c":"n","i":"l","a":"n","score":"4.3","severity":"m","exploitable":"2.8","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:L\/A:N","score":"4.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"unchanged","c":"none","i":"low","a":"none","exploitable":"2.8","impact":"1.4"},"cwe":[{"cwe":"CWE-352","name":"Cross-Site Request Forgery (CSRF)","description":"The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"1dc5ba1c329a0d865db2c56fbff296f8b019084c855bff536f59ab6652a2bfd7","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.13.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.13.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-11924","name":"CVE-2025-11924","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-11924","description":"[en] The Ninja Forms \u2013 The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.13.2. This is due to the plugin not properly verifying that a user is authorized before the `ninja-forms-views` REST endpoints return form metadata and submission content. This makes it possible for unauthenticated attackers to read arbitrary form definitions and submission records via a leaked bearer token granted they can load any page containing the Submissions Table block. NOTE: The developer released a patch for this issue in 3.13.1, but inadvertently introduced a REST API endpoint in which a valid bearer token could be minted for arbitrary form IDs, making this patch ineffective.","date":"2025-12-17"},{"id":"3292225f60fffef8f00c578138a60641a2402067","name":"Ninja Forms \u2013 The Contact Form Builder That Grows With You <= 3.13.2 - Insecure Direct Object Reference to Unauthenticated Sensitive Information Exposure via Unscoped Bearer Token","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ninja-forms\/ninja-forms-the-contact-form-builder-that-grows-with-you-3132-insecure-direct-object-reference-to-unauthenticated-sensitive-information-exposure-via-unscoped-bearer-token","description":"The Ninja Forms \u2013 The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.13.2. This is due to the plugin not properly verifying that a user is authorized before the `ninja-forms-views` REST endpoints return form metadata and submission content. This makes it possible for unauthenticated attackers to read arbitrary form definitions and submission records via a leaked bearer token granted they can load any page containing the Submissions Table block. NOTE: The developer released a patch for this issue in 3.13.1, but inadvertently introduced a REST API endpoint in which a valid bearer token could be minted for arbitrary form IDs, making this patch ineffective.","date":"2025-12-16"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"h","i":"n","a":"n","score":"7.5","severity":"h","exploitable":"3.9","impact":"3.6"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:N\/A:N","score":"7.5","severity":"high","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"high","i":"none","a":"none","exploitable":"3.9","impact":"3.6"},"cwe":[{"cwe":"CWE-639","name":"Authorization Bypass Through User-Controlled Key","description":"The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"b0de64a76e6319d8fb46913f3d44f8dc5ea10543302e700b1f328d18f5102369","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.13.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.13.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-14072","name":"CVE-2025-14072","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-14072","description":"[en] The Ninja Forms  WordPress plugin before 3.13.3 allows unauthenticated attackers to generate valid access tokens via the REST API which can then be used to read form submissions.","date":"2026-01-02"},{"id":"1844daef7ab5690e39c1578cd9b3b6b0c6eb29f3","name":"Ninja Forms <= 3.13.2 - Missing Authorization to Unauthenticated Submission Disclosure","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ninja-forms\/ninja-forms-3132-missing-authorization-to-unauthenticated-submission-disclosure","description":"The Ninja Forms \u2013 The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the \/ninja-forms-views\/token\/refresh function in all versions up to, and including, 3.13.2. This makes it possible for unauthenticated attackers to generate a token and view arbitrary form submissions. This is a duplicate of CVE-2025-11924.","date":"2025-12-12"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"l","i":"n","a":"n","score":"5.3","severity":"m","exploitable":"3.9","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","score":"5.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"low","i":"none","a":"none","exploitable":"3.9","impact":"1.4"},"cwe":[{"cwe":"CWE-287","name":"Improper Authentication","description":"When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"ae8a509b08add99491a4ca9c98e961f5ccc80a13786045839a45c5aaa00e0438","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.14.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.14.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-1307","name":"Ninja Forms <= 3.14.1 - Authenticated (Contributor+) Sensitive Information Disclosure via Block Editor Token","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-1307","description":"The Ninja Forms - The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.14.1 via a callback function for the admin_enqueue_scripts action handler in blocks\/bootstrap.php. This makes it possible for authenticated attackers, with Contributor-level access and above, to gain access to an authorization token to view form submissions for arbitrary forms, which could potentially contain sensitive information.","date":"0000-00-00"},{"id":"ed7c4d951a34b8e629d40c01e7f2956663abf6b5","name":"Ninja Forms <= 3.14.1 - Authenticated (Contributor+) Sensitive Information Disclosure via Block Editor Token","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ninja-forms\/ninja-forms-3141-authenticated-contributor-sensitive-information-disclosure-via-block-editor-token","description":"The Ninja Forms - The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.14.1 via a callback function for the admin_enqueue_scripts action handler in blocks\/bootstrap.php. This makes it possible for authenticated attackers, with Contributor-level access and above, to gain access to an authorization token to view form submissions for arbitrary forms, which could potentially contain sensitive information.","date":"2026-03-27"}],"impact":{"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"6302f7ab577bcc73e9ef3df1aa191671e138369c5552a84d8dc5243dbb3b9d33","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.14.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.14.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-2268","name":"Ninja Forms <= 3.14.0 - Unauthenticated Information Disclosure in nf_ajax_submit AJAX Action","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-2268","description":"The Ninja Forms plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.14.0. This is due to the unsafe application of the `ninja_forms_merge_tags` filter to user-supplied input within repeater fields, which allows the resolution of `{post_meta:KEY}` merge tags without authorization checks. This makes it possible for unauthenticated attackers to extract arbitrary post metadata from any post on the site, including sensitive data such as WooCommerce billing emails, API keys, private tokens, and customer personal information via the `nf_ajax_submit` AJAX action.","date":"0000-00-00"},{"id":"5031221f5f07ed95ee1deb979f5deb66671c99a9","name":"Ninja Forms <= 3.14.0 - Unauthenticated Information Disclosure in nf_ajax_submit AJAX Action","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ninja-forms\/ninja-forms-3140-unauthenticated-information-disclosure-in-nf-ajax-submit-ajax-action","description":"The Ninja Forms plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.14.0. This is due to the unsafe application of the `ninja_forms_merge_tags` filter to user-supplied input within repeater fields, which allows the resolution of `{post_meta:KEY}` merge tags without authorization checks. This makes it possible for unauthenticated attackers to extract arbitrary post metadata from any post on the site, including sensitive data such as WooCommerce billing emails, API keys, private tokens, and customer personal information via the `nf_ajax_submit` AJAX action.","date":"2026-02-09"}],"impact":{"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"83758347ba55dc8f5d1168c79e9412d8139e57d33c8130899eae4f42ef544227","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.11.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.11.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-9083","name":"Ninja-forms < 3.11.1 - Unauthenticated PHP Objection","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-9083","description":"The Ninja Forms  WordPress plugin before 3.11.1 unserializes user input via form field, which could allow Unauthenticated users to perform PHP Object Injection when a suitable gadget is present on the blog.","date":"0000-00-00"},{"id":"b7014d0fbb26541903750c4e6cac7e72c704d4c4","name":"Ninja Forms <= 3.11.0 - Unauthenticated PHP Object Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ninja-forms\/ninja-forms-3110-unauthenticated-php-object-injection","description":"The Ninja Forms \u2013 The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.11.0 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target system, it may allow the attacker to perform actions like delete arbitrary files, retrieve sensitive data, or execute code depending on the POP chain present.","date":"2025-08-28"},{"id":"EUVD-2025-29844","name":"EUVD-2025-29844","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2025-29844","description":"The Ninja Forms  WordPress plugin before 3.11.1 unserializes user input via form field, which could allow Unauthenticated users to perform PHP Object Injection when a suitable gadget is present on the blog.","date":"2025-09-18"}],"impact":{"ssvc":{"exploitation":"poc","automatable":"yes","technical_impact":"total","kev":false,"kev_date":null},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"9.8","severity":"critical","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":null,"impact":null},"epss":"0.001"}},{"uuid":"a90a22c0c03552cbfc637bc129f5428eabe88e3a16a37be45287d0eac492e1e4","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.14.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.14.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-1239","name":"CVE-2026-1239","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-1239","description":"[en] The Ninja Forms \u2013 The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to unauthorized access of data due to a missing authorization check on the 'ninja-forms-views\/token\/refresh' REST callback in all versions up to, and including, 3.14.1. This makes it possible for unauthenticated attackers to view form submissions, which could potentially contain sensitive information.","date":"2026-07-01"},{"id":"70136b85905aa4520cc37b53767d07be2600b1be","name":"Ninja Forms <= 3.14.1 - Missing Authorization to Unauthenticated Sensitive Information Disclosure via token\/refresh REST Endpoint","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ninja-forms\/ninja-forms-3141-missing-authorization-to-unauthenticated-sensitive-information-disclosure-via-tokenrefresh-rest-endpoint","description":"The Ninja Forms \u2013 The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to unauthorized access of data due to a missing authorization check on the 'ninja-forms-views\/token\/refresh' REST callback in all versions up to, and including, 3.14.1. This makes it possible for unauthenticated attackers to view form submissions, which could potentially contain sensitive information.","date":"2026-06-30"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"h","i":"n","a":"n","score":"7.5","severity":"h","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:N\/A:N","score":"7.5","severity":"high","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"high","i":"none","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"b03e069befd2c288c5633a27e876c751e5e8ed9327f777b72bab2673d1b8c1c5","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] <= 3.14.8 (unfixed)","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.14.8","max_operator":"le","unfixed":"1","closed":"0"},"source":[{"id":"CVE-2026-65052","name":"CVE-2026-65052","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-65052","description":"[en] Ninja Forms WordPress plugin version 3.14.8 and prior contains an improper input validation vulnerability that allows unauthenticated attackers to inject arbitrary numeric values into form calculations and payment totals by submitting values that do not match any configured option in ListSelect or ListRadio fields. Attackers can tamper with form submission payloads to the ajax submit endpoint, causing the get_calc_value() method to fail open and return attacker-controlled values, enabling manipulation of payment amounts to zero or arbitrary figures and bypassing admin-configured pricing logic.","date":"2026-07-21"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:H\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"n","i":"h","a":"n","score":"7.5","severity":"h","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:H\/A:N","score":"7.5","severity":"high","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"none","i":"high","a":"none","exploitable":"0.0","impact":"0.0"},"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"c6b3cb96551023c1020a27052db71a05aa46fd040f8c450759b22b509c22c0b6","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] <= 3.14.8 (unfixed)","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.14.8","max_operator":"le","unfixed":"1","closed":"0"},"source":[{"id":"CVE-2026-65051","name":"CVE-2026-65051","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-65051","description":"[en] Ninja Forms WordPress plugin version 3.14.8 contains a client-side enforcement of server-side security vulnerability that allows unauthenticated attackers to bypass all form validation by merging attacker-controlled field metadata over server-loaded form definitions before validation runs. Attackers can craft a malicious AJAX submission overriding field types, removing required flags, and disabling CAPTCHA checks through the nopriv AJAX endpoint to trigger form actions such as email notifications and database storage with unverified, attacker-controlled content.","date":"2026-07-21"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:L\/A:L","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"n","i":"l","a":"l","score":"6.5","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:L\/A:L","score":"6.5","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"none","i":"low","a":"low","exploitable":"0.0","impact":"0.0"},"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"e397209245028a57d69b60de5f550d322859075c799bae00c88f446bcc00831c","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] <= 3.14.8 (unfixed)","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.14.8","max_operator":"le","unfixed":"1","closed":"0"},"source":[{"id":"CVE-2026-65050","name":"CVE-2026-65050","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-65050","description":"[en] Ninja Forms WordPress plugin version 3.14.8 and prior contains a missing authorization vulnerability in the render callback of the `ninja-forms\/submissions-table` Gutenberg block that allows authenticated attackers with Author-level privileges to expose stored form submissions to unauthenticated visitors by embedding the block with an arbitrary formID on a published post. Attackers can retrieve the signed bearer token injected into every page visitor's browser via `wp_localize_script` and use it against the REST API submissions endpoint to access all saved form submission field values, including sensitive personally identifiable information such as names, email addresses, and phone numbers.","date":"2026-07-21"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:N\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"h","i":"n","a":"n","score":"6.5","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:N\/A:N","score":"6.5","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"high","i":"none","a":"none","exploitable":"0.0","impact":"0.0"},"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"a04cdfefbb1b55455ce56a9b7ec0e4cf588c8dc0985b494ac671662ff448243a","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] <= 3.14.8 (unfixed)","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.14.8","max_operator":"le","unfixed":"1","closed":"0"},"source":[{"id":"CVE-2026-65049","name":"CVE-2026-65049","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-65049","description":"[en] Ninja Forms plugin version 3.14.8 and prior for WordPress Multisite contains an incorrect authorization vulnerability that allows a subsite Administrator to trigger network-wide deletion of all Ninja Forms data by exploiting a site-scoped capability check combined with unsafe multisite migration defaults. Attackers can send a crafted POST request to the admin-ajax.php endpoint with the nf_delete_all_data action and a per-site nonce to invoke migration routines that unconditionally iterate all blogs via switch_to_blog(), dropping all nf3_* tables and clearing options and transients across every subsite in the network without requiring super-admin or network-admin privileges.","date":"2026-07-21"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:N\/I:H\/A:H","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"n","i":"h","a":"h","score":"9.3","severity":"c","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:N\/I:H\/A:H","score":"9.3","severity":"critical","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"none","i":"high","a":"high","exploitable":"0.0","impact":"0.0"},"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"73e84e27712f918787662e151080cf6ac46dfc59f45d830fe81a0b36a2221817","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] <= 3.10.4 (unfixed)","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.10.4","max_operator":"le","unfixed":"1","closed":"0"},"source":[{"id":"CVE-2026-65048","name":"CVE-2026-65048","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-65048","description":"[en] Ninja Forms plugin for WordPress versions 3.10.4 through 3.14.9 contains an unauthenticated stored cross-site scripting vulnerability in the Repeatable Fieldset feature where parseSubmissionIndex() accepts arbitrary strings as submission indexes without numeric validation, and admin_form_element() interpolates the index directly into HTML without escaping. An unauthenticated attacker can submit a public form with a crafted repeater child key containing malicious script payloads, which execute in an administrator's browser when viewing submissions in the WordPress admin panel, enabling session-cookie theft, creation of administrator accounts, installation of malicious plugins, and arbitrary modification of site content.","date":"2026-07-21"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:H\/I:H\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"h","i":"h","a":"n","score":"9.3","severity":"c","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:H\/I:H\/A:N","score":"9.3","severity":"critical","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"high","i":"high","a":"none","exploitable":"0.0","impact":"0.0"},"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"96d1ea0fede08c76a71c193745033e64ac99afc21d1cdbba8b7e28eaeec21fda","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.14.10","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.14.10","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-15663","name":"Ninja Forms <= 3.14.9 - Authenticated (Administrator+) SQL Injection via Import File 'settings' Key","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-15663","description":"The Ninja Forms \u2013 The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to generic SQL Injection via Import File 'settings' Key in all versions up to, and including, 3.14.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. The vulnerable keys originate from the 'settings' object in an attacker-controlled import file processed via file_get_contents() or base64-decoded\/JSON-decoded blobs, bypassing wp_magic_quotes protections entirely; two distinct sinks are affected \u2014 _save_setting() in Model.php and insert_form_meta() in ImportForm.php \u2014 as only the value side is escaped while the key side receives no sanitization or parameterization at any point in the call chain.","date":"0000-00-00"},{"id":"61f9ff7d5cb53fe5a0d07d5a058d8ae23ca98034","name":"Ninja Forms <= 3.14.9 - Authenticated (Administrator+) SQL Injection via Import File 'settings' Key","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ninja-forms\/ninja-forms-3149-authenticated-administrator-sql-injection-via-import-file-settings-key","description":"The Ninja Forms \u2013 The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to generic SQL Injection via Import File 'settings' Key in all versions up to, and including, 3.14.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. The vulnerable keys originate from the 'settings' object in an attacker-controlled import file processed via file_get_contents() or base64-decoded\/JSON-decoded blobs, bypassing wp_magic_quotes protections entirely; two distinct sinks are affected \u2014 _save_setting() in Model.php and insert_form_meta() in ImportForm.php \u2014 as only the value side is escaped while the key side receives no sanitization or parameterization at any point in the call chain.","date":"2026-07-23"}],"impact":{"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"cad76acf5acb5e55395fde2f1e6b2f6f3cdf20704e81127d654d896547d8d4b3","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.14.10","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.14.10","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-15256","name":"CVE-2026-15256","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-15256","description":"[en] The Ninja Forms WordPress plugin before 3.14.10 does not prevent user-supplied query-string input, used to pre-populate a form field's default value, from being processed as a shortcode, allowing unauthenticated attackers to execute arbitrary shortcodes registered on the site when a form so configured is embedded on a public page.","date":"2026-08-06"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:H\/PR:N\/UI:N\/S:U\/C:L\/I:L\/A:N","av":"n","ac":"h","pr":"n","ui":"n","s":"u","c":"l","i":"l","a":"n","score":"4.8","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:H\/PR:N\/UI:N\/S:U\/C:L\/I:L\/A:N","score":"4.8","severity":"medium","av":"network","ac":"high","pr":"none","ui":"none","s":"unchanged","c":"low","i":"low","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-74","name":"Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')","description":"The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component."}],"ssvc":{"exploitation":"poc","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"90d89e8d905ced13b835ead0ccfa1a77861a5bfff337f66fab6ecb02d8652e7e","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.15.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.15.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-80438","name":"CVE-2026-80438","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-80438","description":"[en] The Ninja Forms  WordPress plugin before 3.15.2 does not restrict its REST abilities to administrators, accepting a Ninja Forms  WordPress plugin before 3.15.2-specific capability as equivalent to full site administration, which allows any user granted that capability to read Ninja Forms  WordPress plugin before 3.15.2 settings and stored form submissions, overwrite the Ninja Forms  WordPress plugin before 3.15.2's configuration, and create or modify arbitrary posts and pages.\nThe capability belongs to no default WordPress role and the Ninja Forms  WordPress plugin before 3.15.2 never grants it, so an administrator must have assigned it, typically when delegating access to the form builder.","date":"2026-09-04"},{"id":"7d8367eae98a1be85797521a911f37d0a5b9d8da","name":"Ninja Forms \u2013 The Contact Form Builder That Grows With You 3.14.0 - 3.15.1 - Authenticated (Custom Role+) Information Exposure","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ninja-forms\/ninja-forms-the-contact-form-builder-that-grows-with-you-3140-3151-authenticated-custom-role-information-exposure","description":"The Ninja Forms \u2013 The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Sensitive Information Exposure in versions 3.14.0 through 3.15.1. This makes it possible for authenticated attackers, with custom role-level access and above, to extract sensitive user or configuration data.","date":"2026-09-08"}],"impact":{"cwe":[{"cwe":"CWE-284","name":"Improper Access Control","description":"The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"9cab4fefa8e3d58669c9337cc677adb4b1f9915fa5bf3fb4eb0f9be984ce106b","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.15.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.15.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-19769","name":"CVE-2026-19769","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-19769","description":"[en] The Ninja Forms \u2013 The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Repeater Child 'type' Confusion via Unmatched Array Key in all versions up to, and including, 3.15.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires the Ninja Forms File Uploads add-on to be active, as the attack routes the unwhitelisted child entry through the File Uploads handler to write an attacker-supplied HTML file containing arbitrary JavaScript into any web-server-writable directory, including the site root, where it is served from the site's own origin.","date":"2026-09-05"},{"id":"664eb5324fc5f9f9db67c23e01c2fec8e54e7815","name":"Ninja Forms <= 3.15.1 - Unauthenticated Stored Cross-Site Scripting via Repeater Child 'type' Confusion via Unmatched Array Key","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ninja-forms\/ninja-forms-3151-unauthenticated-stored-cross-site-scripting-via-repeater-child-type-confusion-via-unmatched-array-key","description":"The Ninja Forms \u2013 The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Repeater Child 'type' Confusion via Unmatched Array Key in all versions up to, and including, 3.15.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires the Ninja Forms File Uploads add-on to be active, as the attack routes the unwhitelisted child entry through the File Uploads handler to write an attacker-supplied HTML file containing arbitrary JavaScript into any web-server-writable directory, including the site root, where it is served from the site's own origin.","date":"2026-07-23"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"c","c":"l","i":"l","a":"n","score":"7.2","severity":"h","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:C\/C:L\/I:L\/A:N","score":"7.2","severity":"high","av":"network","ac":"low","pr":"none","ui":"none","s":"changed","c":"low","i":"low","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"8ebd3fb5af5e52fab85b7f77a558a33295f2858b56332698faf1d57958b35b83","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.15.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.15.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-80437","name":"CVE-2026-80437","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-80437","description":"[en] The Ninja Forms WordPress plugin from 3.14.10 before 3.15.2 does not prevent shortcodes in request-derived values from being executed when it substitutes them into content it later processes for shortcodes, allowing unauthenticated users to run any shortcode registered on the site.","date":"2026-09-06"},{"id":"EUVD-2026-72092","name":"EUVD-2026-72092","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2026-72092","description":"The Ninja Forms WordPress plugin from 3.14.10 before 3.15.2 does not prevent shortcodes in request-derived values from being executed when it substitutes them into content it later processes for shortcodes, allowing unauthenticated users to run any shortcode registered on the site.","date":"2026-09-06"},{"id":"4cecf746bb2374834ae7854e24afdf9f82dcc5e7","name":"Ninja Forms \u2013 The Contact Form Builder That Grows With You 3.14.10 - 3.15.1 - Unauthenticated Arbitrary Shortcode Execution","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ninja-forms\/ninja-forms-the-contact-form-builder-that-grows-with-you-31410-3151-unauthenticated-arbitrary-shortcode-execution","description":"The Ninja Forms \u2013 The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Remote Code Execution in versions 3.14.10 through 3.15.1. This is due to missing neutralization of shortcode brackets in the system_ip and referer_url merge tag sources in both MergeTags\/Other.php and MergeTags\/Deprecated.php before their values are processed by do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes registered on the site by supplying crafted bracket sequences in request-derived merge tag values such as the client IP address or referer URL.","date":"2026-09-08"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:H\/PR:N\/UI:N\/S:U\/C:L\/I:L\/A:N","av":"n","ac":"h","pr":"n","ui":"n","s":"u","c":"l","i":"l","a":"n","score":"4.8","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:H\/PR:N\/UI:N\/S:U\/C:L\/I:L\/A:N","score":"4.8","severity":"medium","av":"network","ac":"high","pr":"none","ui":"none","s":"unchanged","c":"low","i":"low","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-74","name":"Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')","description":"The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"73abad1ca5404a801a361de5fdc065e7505db4cc3af696f039cd4f250f0807ec","name":"Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.14.7","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.14.7","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-11363","name":"CVE-2026-11363","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-11363","description":"[en] The Ninja Forms \u2013 The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.14.6 via deserialization of untrusted input . This makes it possible for authenticated attackers, with administrator-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target system, it may allow the attacker to perform actions like delete arbitrary files, retrieve sensitive data, or execute code depending on the POP chain present. The deserialization is triggered automatically during form import when WPN_Helper::build_nf_cache() invokes $action->get_settings() immediately after the crafted form is imported, requiring no further interaction beyond the import action itself.","date":"2026-09-09"},{"id":"2e33fb3f969417892e93026235941feba6da242d","name":"Ninja Forms <= 3.14.6 - Authenticated (Administrator+) PHP Object Injection via Form Import","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ninja-forms\/ninja-forms-3146-authenticated-administrator-php-object-injection-via-form-import","description":"The Ninja Forms \u2013 The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.14.6 via deserialization of untrusted input . This makes it possible for authenticated attackers, with administrator-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target system, it may allow the attacker to perform actions like delete arbitrary files, retrieve sensitive data, or execute code depending on the POP chain present. The deserialization is triggered automatically during form import when WPN_Helper::build_nf_cache() invokes $action->get_settings() immediately after the crafted form is imported, requiring no further interaction beyond the import action itself.","date":"2026-09-04"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:H\/PR:H\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"h","pr":"h","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"6.6","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:H\/PR:H\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"6.6","severity":"medium","av":"network","ac":"high","pr":"high","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-502","name":"Deserialization of Untrusted Data","description":"The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"total","kev":false,"kev_date":null}}}]},"updated":"1789031527"}