PT-2023-6578 · WordPress · Ninja Forms Contact Form

Erwan Lr

·

Published

2023-04-24

·

Updated

2025-01-14

·

CVE-2023-1835

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Ninja Forms Contact Form WordPress plugin versions prior to 3.6.22
Description The issue is related to the lack of protection of the web page structure, allowing for reflected cross-site scripting attacks. This could enable a remote attacker to conduct inter-site script attacks. The vulnerability arises from the improper escaping of user input before it is outputted back in an admin page, which could be used against high-privilege users such as administrators.
Recommendations For versions prior to 3.6.22, update to version 3.6.22 or later to resolve the issue. As a temporary workaround, consider restricting access to admin pages to minimize the risk of exploitation. Avoid using the plugin until the issue is resolved.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

BDU:2023-07342
CVE-2023-1835

Affected Products

Ninja Forms Contact Form