Lucene search

K
wpvulndbWpvulndbWPVDB-ID:7CF362C9-6E53-40CC-9AF1-519B41C835D7
HistoryMay 09, 2024 - 12:00 a.m.

Ninja Forms – The Contact Form Builder That Grows With You < 3.8.1 - Admin+ Stored Cross-Site Scripting

2024-05-0900:00:00
wpscan.com
2
ninja forms
wordpress
stored xss

5.8 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

15.5%

Description The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a form field in all versions up to, and including, 3.8.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

CPENameOperatorVersion
eq3.8.1

5.8 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

15.5%

Related for WPVDB-ID:7CF362C9-6E53-40CC-9AF1-519B41C835D7