Lucene search

K
vulnrichmentWPScanVULNRICHMENT:CVE-2024-7354
HistorySep 02, 2024 - 6:00 a.m.

CVE-2024-7354 Ninja Forms 3.8.6-3.8.10 - Reflected XSS

2024-09-0206:00:01
WPScan
github.com
8
ninja forms
xss
vulnerability
wordpress
plugin
attribute
url
high privilege users
admin

AI Score

6.2

Confidence

High

SSVC

Exploitation

poc

Automatable

no

Technical Impact

partial

The Ninja Forms WordPress plugin before 3.8.11 does not escape an URL before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

ADP Affected

[
  {
    "cpes": [
      "cpe:2.3:a:ninjaforms:ninja_forms:*:*:*:*:*:wordpress:*:*"
    ],
    "vendor": "ninjaforms",
    "product": "ninja_forms",
    "versions": [
      {
        "status": "affected",
        "version": "0",
        "lessThan": "3.8.11",
        "versionType": "semver"
      }
    ],
    "defaultStatus": "unknown"
  }
]

AI Score

6.2

Confidence

High

SSVC

Exploitation

poc

Automatable

no

Technical Impact

partial

Related for VULNRICHMENT:CVE-2024-7354