cleantalk
Vulnerabilities and Security Researches

Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress, CVE-2018-19796

CVE, Research URL

CVE-2018-19796

Published on
Dec 03, 2018
Research Description
An open redirect in the Ninja Forms plugin before 3.3.19.1 for WordPress allows Remote Attackers to redirect a user via the lib/StepProcessing/step-processing.php (aka submissions download page) redirect parameter.
Affected versions
Min -, max 3.3.19.1.
Status
vulnerable