ThreatPress

WordPress Vulnerability Database

Back

WordPress Ninja Forms Contact Form plugin <= 3.4.33 - Administrator Open Redirect vulnerability

Product
Ninja Forms
Description
Administrator Open Redirect vulnerability found by Chloe Chamberland in WordPress Ninja Forms Contact Form plugin (versions <= 3.4.33).
Solution
Update the WordPress Ninja Forms Contact Form plugin to the latest available version (at least 3.4.34).
Classification
Type Open Redirection
OWASP Top 10 A10: Unvalidated Redirects and Forwards
References
Vulnerability details
Plugin changelog
CVE
Name CVE-N/A
Versions
Affected In <= 3.4.33
Fixed In 3.4.34
Disclosure date
2021-02-16
Credits
Chloe Chamberland