PT-2023-6578 · WordPress · Ninja Forms Contact Form
Erwan Lr
·
Published
2023-04-24
·
Updated
2025-01-14
·
CVE-2023-1835
CVSS v2.0
6.4
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Ninja Forms Contact Form WordPress plugin versions prior to 3.6.22
Description
The issue is related to the lack of protection of the web page structure, allowing for reflected cross-site scripting attacks. This could enable a remote attacker to conduct inter-site script attacks. The vulnerability arises from the improper escaping of user input before it is outputted back in an admin page, which could be used against high-privilege users such as administrators.
Recommendations
For versions prior to 3.6.22, update to version 3.6.22 or later to resolve the issue. As a temporary workaround, consider restricting access to admin pages to minimize the risk of exploitation. Avoid using the plugin until the issue is resolved.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ninja Forms Contact Form