WordPress Ninja Forms Contact Form plugin <= 3.4.33 - Authenticated SendWP Plugin Installation and Client Secret Key Disclosure vulnerability
Product
Ninja Forms
Description
Authenticated SendWP Plugin Installation and Client Secret Key Disclosure vulnerability found by Chloe Chamberland in WordPress Ninja Forms Contact Form plugin (versions <= 3.4.33).
Solution
Update the WordPress Ninja Forms Contact Form plugin to the latest available version (at least 3.4.34).
Classification
Type Unknown OWASP Top 10 A7: Missing Function Level Access Control