PT-2022-10566 · WordPress · Ninja Forms Contact Form

Bugb Hunter

·

Published

2022-06-16

·

Updated

2024-09-16

·

CVE-2021-36827

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Ninja Forms Contact Form plugin versions prior to 3.6.9
Description The issue is related to a Stored Cross-Site Scripting (XSS) vulnerability that requires authentication with admin+ privileges. It affects the Ninja Forms Contact Form plugin at WordPress. The vulnerability can be exploited via the label variable.
Recommendations For versions prior to 3.6.9, update to a version that contains a fix for this issue.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2021-36827

Affected Products

Ninja Forms Contact Form