cleantalk
Vulnerabilities and Security Researches

Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress, CVE-2024-29220

CVE, Research URL

CVE-2024-29220

Published on
Apr 11, 2024
Research Description
Ninja Forms prior to 3.8.1 contains a cross-site scripting vulnerability in custom fields for labels. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who is accessing to the website using the product.
Affected versions
Min -, max 3.8.1.
Status
vulnerable