QID 150388
Date Published: 2021-11-17
QID 150388: WordPress Ninja Forms Plugin Multiple Vulnerabilities
Ninja Forms is a free form builder plugin for WordPress, it provides users the ability to create custom forms using drag and drop capabilities.
Multiple Vulnerabilities are identified in WordPress Ninja Forms plugin before version 3.4.34.1:
CVE-2021-24163: Authenticated SendWP Plugin Installation and Client Secret Key Disclosure
CVE-2021-24164: Authenticated OAuth Connection Key Disclosure
CVE-2021-24165: Administrator Open Redirect
CVE-2021-24166: CSRF to OAuth Service Disconnection
NOTE: CVE-2021-24163,CVE-2021-24165 and CVE-2021-24166 are not applicable for Ninja forms version 3.4.34
Successful exploitation would lead remote attackers to gain access to sensitive information and launch further attacks against the affected system.
Solution
Customers are advised to upgrade to a fixed version Ninja Forms 3.4.34.1 or later versions to remediate this vulnerability.
Vendor References
CVEs related to QID 150388
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Ninja Forms |
|