Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Rodel Plasabas

#50227of 53,632
4.8Total CVSS
Vulnerabilities · 1
PT-2021-15914
4.8
2021-10-25
WordPress · Ninja Forms Contact Form · CVE-2021-24381
**Name of the Vulnerable Software and Affected Versions** Ninja Forms Contact Form WordPress plugin versions prior to 3.5.8.2 **Description** The issue allows high privilege users to perform Cross-Site Scripting attacks due to the lack of sanitization and escaping of the custom class name of the form field created. This is possible even when the unfiltered html capability is disallowed. **Recommendations** For versions prior to 3.5.8.2, update to version 3.5.8.2 or later to resolve the issue.