QID 150388

Date Published: 2021-11-17

QID 150388: WordPress Ninja Forms Plugin Multiple Vulnerabilities

Ninja Forms is a free form builder plugin for WordPress, it provides users the ability to create custom forms using drag and drop capabilities.

Multiple Vulnerabilities are identified in WordPress Ninja Forms plugin before version 3.4.34.1:
CVE-2021-24163: Authenticated SendWP Plugin Installation and Client Secret Key Disclosure
CVE-2021-24164: Authenticated OAuth Connection Key Disclosure
CVE-2021-24165: Administrator Open Redirect
CVE-2021-24166: CSRF to OAuth Service Disconnection

NOTE: CVE-2021-24163,CVE-2021-24165 and CVE-2021-24166 are not applicable for Ninja forms version 3.4.34

Successful exploitation would lead remote attackers to gain access to sensitive information and launch further attacks against the affected system.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as High - 6.5 severity.
  • Solution
    Customers are advised to upgrade to a fixed version Ninja Forms 3.4.34.1 or later versions to remediate this vulnerability.

    CVEs related to QID 150388

    Software Advisories
    Advisory ID Software Component Link
    Ninja Forms URL Logo ninjaforms.com/account/downloads/