cleantalk
Vulnerabilities and Security Researches

Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress, cec7d366-7663-4b83-9640-a58f2fcf5e41

Published on
-
Research Description
Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.6.8 Ninja Forms &lt; 3.6.8 - Unauthenticated Email Address Disclosure The plugin does not delete the temporary files created when exporting submissions, which could allow unauthenticated attackers to download them and get sensitive information such as the email address of users who submitted a form given that the file is publicly accessible, and with a guessable name
Affected versions
max 3.6.8.
Status
vulnerable