PT-2021-20615 · WordPress · Ninja Forms
Chloe Chamberland
·
Published
2021-09-22
·
Updated
2022-10-27
·
CVE-2021-34647
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Ninja Forms WordPress plugin versions up to and including 3.5.7
Description:
The issue allows authenticated attackers to export all Ninja Forms submissions data via the "/ninja-forms-submissions/export" REST API, which can include personally identifiable information. This is due to sensitive information disclosure via the
bulk export submissions function found in the ~/includes/Routes/Submissions.php file.Recommendations:
For versions up to and including 3.5.7, update to a version later than 3.5.7 to resolve the issue.
As a temporary workaround, consider restricting access to the
/ninja-forms-submissions/export REST API endpoint until a patch is available.
Avoid using the bulk export submissions function in the affected versions until the issue is resolved.Exploit
Fix
Incorrect Authorization
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ninja Forms