Back
WordPress Ninja Forms Contact Form plugin <= 3.4.33 - Administrator Open Redirect vulnerability
- Product
- Ninja Forms
- Description
- Administrator Open Redirect vulnerability found by Chloe Chamberland in WordPress Ninja Forms Contact Form plugin (versions <= 3.4.33).
- Solution
- Update the WordPress Ninja Forms Contact Form plugin to the latest available version (at least 3.4.34).
- Classification
-
Type Open Redirection
OWASP Top 10 A10: Unvalidated Redirects and Forwards
- References
-
Vulnerability details
Plugin changelog
- CVE
- Name CVE-N/A
- Versions
-
Affected In
<= 3.4.33
Fixed In 3.4.34
- Disclosure date
- 2021-02-16
- Credits
- Chloe Chamberland