cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forninja-forms ninja-forms

Direction: ascending
Jun 06, 2024

Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress # CVE-2021-24381

CVE, Research URL

CVE-2021-24381

Date
Oct 25, 2021
Research Description
The Ninja Forms Contact Form WordPress plugin before 3.5.8.2 does not sanitise and escape the custom class name of the form field created, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
Affected versions
Min -, max -.
Status
vulnerable

Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress # CVE-2021-24163

CVE, Research URL

CVE-2021-24163

Date
Apr 06, 2021
Research Description
The AJAX action, wp_ajax_ninja_forms_sendwp_remote_install_handler, did not have a capability check on it, nor did it have any nonce protection, therefore making it possible for low-level users, such as subscribers, to install and activate the SendWP Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress WordPress plugin before 3.4.34 and retrieve the client_secret key needed to establish the SendWP connection while also installing the SendWP plugin.
Affected versions
Min -, max -.
Status
vulnerable

Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress # CVE-2021-24889

CVE, Research URL

CVE-2021-24889

Date
Nov 29, 2021
Research Description
The Ninja Forms Contact Form WordPress plugin before 3.6.4 does not escape keys of the fields POST parameter, which could allow high privilege users to perform SQL injections attacks
Affected versions
Min -, max -.
Status
vulnerable

Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress # CVE-2021-34647

CVE, Research URL

CVE-2021-34647

Date
Sep 22, 2021
Research Description
The Ninja Forms WordPress plugin is vulnerable to sensitive information disclosure via the bulk_export_submissions function found in the ~/includes/Routes/Submissions.php file, in versions up to and including 3.5.7. This allows authenticated attackers to export all Ninja Forms submissions data via the /ninja-forms-submissions/export REST API which can include personally identifiable information.
Affected versions
Min -, max -.
Status
vulnerable

Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress # CVE-2021-24164

CVE, Research URL

CVE-2021-24164

Date
Apr 06, 2021
Research Description
In the Ninja Forms Contact Form WordPress plugin before 3.4.34.1, low-level users, such as subscribers, were able to trigger the action, wp_ajax_nf_oauth, and retrieve the connection url needed to establish a connection. They could also retrieve the client_id for an already established OAuth connection.
Affected versions
Min -, max -.
Status
vulnerable

Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress # CVE-2020-36173

CVE, Research URL

CVE-2020-36173

Date
Jan 06, 2021
Research Description
The Ninja Forms plugin before 3.4.28 for WordPress lacks escaping for submissions-table fields.
Affected versions
Min -, max -.
Status
vulnerable

Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress # CVE-2020-36174

CVE, Research URL

CVE-2020-36174

Date
Jan 06, 2021
Research Description
The Ninja Forms plugin before 3.4.27.1 for WordPress allows CSRF via services integration.
Affected versions
Min -, max -.
Status
vulnerable

Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress # CVE-2020-8594

CVE, Research URL

CVE-2020-8594

Date
Feb 15, 2020
Research Description
The Ninja Forms plugin 3.4.22 for WordPress has Multiple Stored XSS vulnerabilities via ninja_forms[recaptcha_site_key], ninja_forms[recaptcha_secret_key], ninja_forms[recaptcha_lang], or ninja_forms[date_format].
Affected versions
Min -, max -.
Status
vulnerable

Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress # CVE-2018-19796

CVE, Research URL

CVE-2018-19796

Date
Dec 03, 2018
Research Description
An open redirect in the Ninja Forms plugin before 3.3.19.1 for WordPress allows Remote Attackers to redirect a user via the lib/StepProcessing/step-processing.php (aka submissions download page) redirect parameter.
Affected versions
Min -, max -.
Status
vulnerable

Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress # CVE-2018-20981

CVE, Research URL

CVE-2018-20981

Date
Aug 22, 2019
Research Description
The ninja-forms plugin before 3.3.9 for WordPress has insufficient restrictions on submission-data retrieval during Export Personal Data requests.
Affected versions
Min -, max -.
Status
vulnerable

Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress # CVE-2021-34648

CVE, Research URL

CVE-2021-34648

Date
Sep 22, 2021
Research Description
The Ninja Forms WordPress plugin is vulnerable to arbitrary email sending via the trigger_email_action function found in the ~/includes/Routes/Submissions.php file, in versions up to and including 3.5.7. This allows authenticated attackers to send arbitrary emails from the affected server via the /ninja-forms-submissions/email-action REST API which can be used to socially engineer victims.
Affected versions
Min -, max -.
Status
vulnerable

Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress # CVE-2021-24166

CVE, Research URL

CVE-2021-24166

Date
Apr 06, 2021
Research Description
The wp_ajax_nf_oauth_disconnect from the Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress WordPress plugin before 3.4.34 had no nonce protection making it possible for attackers to craft a request to disconnect a site's OAuth connection.
Affected versions
Min -, max -.
Status
vulnerable

Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress # CVE-2020-36175

CVE, Research URL

CVE-2020-36175

Date
Jan 06, 2021
Research Description
The Ninja Forms plugin before 3.4.27.1 for WordPress allows attackers to bypass validation via the email field.
Affected versions
Min -, max -.
Status
vulnerable

Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress # CVE-2020-12462

CVE, Research URL

CVE-2020-12462

Date
Apr 29, 2020
Research Description
The ninja-forms plugin before 3.4.24.2 for WordPress allows CSRF with resultant XSS.
Affected versions
Min -, max -.
Status
vulnerable

Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress # CVE-2018-20980

CVE, Research URL

CVE-2018-20980

Date
Aug 22, 2019
Research Description
The ninja-forms plugin before 3.2.15 for WordPress has parameter tampering.
Affected versions
Min -, max -.
Status
vulnerable

Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress # CVE-2017-18574

CVE, Research URL

CVE-2017-18574

Date
Aug 22, 2019
Research Description
The ninja-forms plugin before 3.0.31 for WordPress has insufficient HTML escaping in the builder.
Affected versions
Min -, max -.
Status
vulnerable

Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress # CVE-2021-24165

CVE, Research URL

CVE-2021-24165

Date
Apr 06, 2021
Research Description
In the Ninja Forms Contact Form WordPress plugin before 3.4.34, the wp_ajax_nf_oauth_connect AJAX action was vulnerable to open redirect due to the use of a user supplied redirect parameter and no protection in place.
Affected versions
Min -, max -.
Status
vulnerable

Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress # CVE-2019-15025

CVE, Research URL

CVE-2019-15025

Date
Aug 14, 2019
Research Description
The ninja-forms plugin before 3.3.21.2 for WordPress has SQL injection in the search filter on the submissions page.
Affected versions
Min -, max -.
Status
vulnerable

Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress # CVE-2014-9688

CVE, Research URL

CVE-2014-9688

Date
Mar 05, 2015
Research Description
Unspecified vulnerability in the Ninja Forms plugin before 2.8.10 for WordPress has unknown impact and remote attack vectors related to admin users.
Affected versions
Min -, max -.
Status
vulnerable

Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress # CVE-2018-19287

CVE, Research URL

CVE-2018-19287

Date
Nov 15, 2018
Research Description
XSS in the Ninja Forms plugin before 3.3.18 for WordPress allows Remote Attackers to execute JavaScript via the includes/Admin/Menus/Submissions.php (aka submissions page) begin_date, end_date, or form_id parameter.
Affected versions
Min -, max -.
Status
vulnerable

Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress # CVE-2018-7280

CVE, Research URL

CVE-2018-7280

Date
Feb 21, 2018
Research Description
The Ninja Forms plugin before 3.2.14 for WordPress has XSS.
Affected versions
Min -, max -.
Status
vulnerable

Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress # CVE-2015-2220

CVE, Research URL

CVE-2015-2220

Date
Mar 05, 2015
Research Description
Multiple cross-site scripting (XSS) vulnerabilities in the Ninja Forms plugin before 2.8.9 for WordPress allow (1) remote attackers to inject arbitrary web script or HTML via the ninja_forms_field_1 parameter in a ninja_forms_ajax_submit action to wp-admin/admin-ajax.php or (2) remote administrators to inject arbitrary web script or HTML via the fields[1] parameter to wp-admin/post.php.
Affected versions
Min -, max -.
Status
vulnerable

Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress # CVE-2018-16308

CVE, Research URL

CVE-2018-16308

Date
Sep 01, 2018
Research Description
The Ninja Forms plugin before 3.3.14.1 for WordPress allows CSV injection.
Affected versions
Min -, max -.
Status
vulnerable

Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress # CVE-2016-1209

CVE, Research URL

CVE-2016-1209

Date
May 14, 2016
Research Description
The Ninja Forms plugin before 2.9.42.1 for WordPress allows remote attackers to conduct PHP object injection attacks via crafted serialized values in a POST request.
Affected versions
Min -, max -.
Status
vulnerable

Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress # CVE-2021-25056

CVE, Research URL

CVE-2021-25056

Date
Jul 04, 2022
Research Description
The Ninja Forms Contact Form WordPress plugin before 3.6.10 does not sanitise and escape field labels, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
Affected versions
Min -, max -.
Status
vulnerable

Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress # CVE-2021-36827

CVE, Research URL

CVE-2021-36827

Date
Jun 16, 2022
Research Description
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Saturday Drive's Ninja Forms Contact Form plugin <= 3.6.9 at WordPress via "label".
Affected versions
Min -, max -.
Status
vulnerable

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # CVE-2021-25066

CVE, Research URL

CVE-2021-25066

Date
Jul 04, 2022
Research Description
The Ninja Forms Contact Form WordPress plugin before 3.6.10 does not sanitize and escape some imported data, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
Affected versions
Min -, max -.
Status
vulnerable

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # CVE-2022-2903

CVE, Research URL

CVE-2022-2903

Date
Sep 26, 2022
Research Description
The Ninja Forms Contact Form WordPress plugin before 3.6.13 unserialises the content of an imported file, which could lead to PHP object injections issues when an admin import (intentionally or not) a malicious file and a suitable gadget chain is present on the blog.
Affected versions
Min -, max -.
Status
vulnerable

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # CVE-2023-37979

CVE, Research URL

CVE-2023-37979

Date
Jul 27, 2023
Research Description
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Saturday Drive Ninja Forms Contact Form plugin <= 3.6.25 versions.
Affected versions
Min -, max -.
Status
vulnerable

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # CVE-2023-1835

CVE, Research URL

CVE-2023-1835

Date
May 15, 2023
Research Description
The Ninja Forms Contact Form WordPress plugin before 3.6.22 does not properly escape user input before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
Affected versions
Min -, max -.
Status
vulnerable

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # CVE-2023-36505

CVE, Research URL

CVE-2023-36505

Date
Apr 17, 2024
Research Description
Improper Input Validation vulnerability in Saturday Drive Ninja Forms Contact Form.This issue affects Ninja Forms Contact Form : from n/a through 3.6.24.
Affected versions
Min -, max -.
Status
vulnerable

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # CVE-2023-35909

CVE, Research URL

CVE-2023-35909

Date
Dec 07, 2023
Research Description
Uncontrolled Resource Consumption vulnerability in Saturday Drive Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress leading to DoS.This issue affects Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress: from n/a through 3.6.25.
Affected versions
Min -, max -.
Status
vulnerable

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # CVE-2023-4109

CVE, Research URL

CVE-2023-4109

Date
Aug 30, 2023
Research Description
The Ninja Forms WordPress Ninja Forms Contact Form WordPress plugin before 3.6.26 was affected by a HTML Injection security vulnerability.
Affected versions
Min -, max -.
Status
vulnerable

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # CVE-2023-5530

CVE, Research URL

CVE-2023-5530

Date
Nov 07, 2023
Research Description
The Ninja Forms Contact Form WordPress plugin before 3.6.34 does not sanitize and escape its label fields, which could allow high privilege users such as admin to perform Stored XSS attacks. Only users with the unfiltered_html capability can perform this, and such users are already allowed to use JS in posts/comments etc however the vendor acknowledged and fixed the issue
Affected versions
Min -, max -.
Status
vulnerable

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # CVE-2024-2113

CVE, Research URL

CVE-2024-2113

Date
Mar 29, 2024
Research Description
The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.8.0. This is due to missing or incorrect nonce validation on the nf_download_all_subs AJAX action. This makes it possible for unauthenticated attackers to trigger an export of a form's submission to a publicly accessible location via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected versions
Min -, max -.
Status
vulnerable

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # CVE-2024-26019

CVE, Research URL

CVE-2024-26019

Date
Apr 11, 2024
Research Description
Ninja Forms prior to 3.8.1 contains a cross-site scripting vulnerability in submit processing. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who is accessing to the website using the product.
Affected versions
Min -, max -.
Status
vulnerable

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # CVE-2024-25572

CVE, Research URL

CVE-2024-25572

Date
Apr 11, 2024
Research Description
Cross-site request forgery (CSRF) vulnerability exists in Ninja Forms prior to 3.4.31. If a website administrator views a malicious page while logging in, unintended operations may be performed.
Affected versions
Min -, max -.
Status
vulnerable

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # CVE-2024-0685

CVE, Research URL

CVE-2024-0685

Date
Feb 02, 2024
Research Description
The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Second Order SQL Injection via the email address value submitted through forms in all versions up to, and including, 3.7.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to inject SQL in their email address that will append additional into the already existing query when an administrator triggers a personal data export.
Affected versions
Min -, max -.
Status
vulnerable

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # CVE-2024-2108

CVE, Research URL

CVE-2024-2108

Date
Mar 29, 2024
Research Description
The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an image title embedded into a form in all versions up to, and including, 3.8.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
Min -, max -.
Status
vulnerable

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # CVE-2024-29220

CVE, Research URL

CVE-2024-29220

Date
Apr 11, 2024
Research Description
Ninja Forms prior to 3.8.1 contains a cross-site scripting vulnerability in custom fields for labels. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who is accessing to the website using the product.
Affected versions
Min -, max -.
Status
vulnerable
Jun 10, 2024

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # CVE-2023-38386

CVE, Research URL

CVE-2023-38386

Date
Jun 19, 2024
Research Description
Missing Authorization vulnerability in Saturday Drive Ninja Forms.This issue affects Ninja Forms: from n/a through 3.6.25.
Affected versions
Min -, max -.
Status
vulnerable

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # CVE-2014-8815

CVE, Research URL

CVE-2014-8815

Date
-
Research Description
The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘update_message’ parameter in versions up to, and including, 2.8.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Affected versions
Min -, max -.
Status
vulnerable

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # CVE-2023-38393

CVE, Research URL

CVE-2023-38393

Date
Jun 19, 2024
Research Description
Missing Authorization vulnerability in Saturday Drive Ninja Forms.This issue affects Ninja Forms: from n/a through 3.6.25.
Affected versions
Min -, max -.
Status
vulnerable
Jul 08, 2024

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # CVE-2024-37934

CVE, Research URL

CVE-2024-37934

Date
Jul 09, 2024
Research Description
Improper Control of Generation of Code ('Code Injection') vulnerability in Saturday Drive Ninja Forms allows Code Injection.This issue affects Ninja Forms: from n/a through 3.8.4.
Affected versions
Min -, max -.
Status
vulnerable
Jul 28, 2024

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # CVE-2024-39628

CVE, Research URL

CVE-2024-39628

Date
Aug 27, 2024
Research Description
Cross-Site Request Forgery (CSRF) vulnerability in Saturday Drive Ninja Forms allows Cross Site Request Forgery.This issue affects Ninja Forms: from n/a through 3.8.6.
Affected versions
Min -, max -.
Status
vulnerable
Sep 01, 2024

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # CVE-2024-43999

CVE, Research URL

CVE-2024-43999

Date
Sep 18, 2024
Research Description
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Saturday Drive Ninja Forms allows Stored XSS.This issue affects Ninja Forms: from n/a through 3.8.11.
Affected versions
Min -, max -.
Status
vulnerable
Sep 03, 2024

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # CVE-2024-7354

CVE, Research URL

CVE-2024-7354

Date
Sep 02, 2024
Research Description
The Ninja Forms WordPress plugin before 3.8.11 does not escape an URL before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
Affected versions
Min -, max -.
Status
vulnerable
Sep 26, 2024

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # CVE-2024-3866

CVE, Research URL

CVE-2024-3866

Date
Sep 25, 2024
Research Description
The Ninja Forms Contact Form plugin for WordPress is vulnerable to Reflected Self-Based Cross-Site Scripting via the 'Referer' header in all versions up to, and including, 3.8.15 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. Successful exploitation of this vulnerability requires "maintenance mode" for a targeted form to be enabled. However, there is no setting available to the attacker or even an administrator-level user to enable this mode. The mode is only enabled during a required update, which is a very short window of time. Additionally, because of the self-based nature of this vulnerability, attackers would have to rely on additional techniques to execute a supplied payload in the context of targeted user.
Affected versions
Min -, max -.
Status
vulnerable
Oct 31, 2024

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # CVE-2024-50515

CVE, Research URL

CVE-2024-50515

Date
Nov 19, 2024
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Saturday Drive Ninja Forms allows Stored XSS.This issue affects Ninja Forms: from n/a through 3.8.16.
Affected versions
Min -, max -.
Status
vulnerable

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # CVE-2024-50514

CVE, Research URL

CVE-2024-50514

Date
Nov 19, 2024
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Saturday Drive Ninja Forms allows Stored XSS.This issue affects Ninja Forms: from n/a through 3.8.16.
Affected versions
Min -, max -.
Status
vulnerable
Dec 13, 2024

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # CVE-2024-11052

CVE, Research URL

CVE-2024-11052

Date
Dec 12, 2024
Research Description
The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the calculations parameter in all versions up to, and including, 3.8.19 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
Min -, max -.
Status
vulnerable
Dec 29, 2024

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # CVE-2024-12238

CVE, Research URL

CVE-2024-12238

Date
Dec 29, 2024
Research Description
The The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.8.22. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for authenticated attackers, with Subscriber-level access and above, to execute arbitrary shortcodes.
Affected versions
Min -, max -.
Status
vulnerable
Feb 01, 2025

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # CVE-2024-13470

CVE, Research URL

CVE-2024-13470

Date
Jan 30, 2025
Research Description
The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in all versions up to, and including, 3.8.24 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
Min -, max -.
Status
vulnerable
May 21, 2025

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # CVE-2025-2524

CVE, Research URL

CVE-2025-2524

Date
May 19, 2025
Research Description
The Ninja Forms WordPress plugin before 3.10.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
Affected versions
Min -, max -.
Status
vulnerable

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # CVE-2025-2561

CVE, Research URL

CVE-2025-2561

Date
May 19, 2025
Research Description
The Ninja Forms WordPress plugin before 3.10.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
Affected versions
Min -, max -.
Status
vulnerable

Ninja Forms Contact Form &#8211; The Drag and Drop Form Builder for WordPress # CVE-2025-2560

CVE, Research URL

CVE-2025-2560

Date
May 19, 2025
Research Description
The Ninja Forms WordPress plugin before 3.10.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
Affected versions
Min -, max -.
Status
vulnerable