PT-2021-15710 · WordPress · Ninja Forms Contact Form

Chloe Chamberland

·

Published

2021-04-05

·

Updated

2022-08-30

·

CVE-2021-24164

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Ninja Forms Contact Form WordPress plugin versions prior to 3.4.34.1
Description: The issue allows low-level users, such as subscribers, to trigger the wp ajax nf oauth action and retrieve the connection URL needed to establish a connection. They can also retrieve the client id for an already established OAuth connection.
Recommendations: For versions prior to 3.4.34.1, update to version 3.4.34.1 or later to resolve the issue.

Exploit

Fix

Missing Authorization

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2021-24164

Affected Products

Ninja Forms Contact Form