CVE-2021-24165: Ninja Forms < 3.4.34 - Administrator Open Redirect
Published Apr 5, 2021
·Updated
In the Ninja Forms Contact Form WordPress plugin before 3.4.34, the wpajaxnfoauthconnect AJAX action was vulnerable to open redirect due to the use of a user supplied redirect parameter and no protection in place.
Affected Software
1 affected component
NinjaForms Ninja Forms Wordpress<3.4.34
Event History
Apr 5, 2021
CVE Published
via MITRE·06:27 PM
Data Sourced
via MITRE·06:27 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2021-24165.
2
What is the severity of CVE-2021-24165?
The severity of CVE-2021-24165 is medium.
3
What is the affected software?
The affected software is the Ninja Forms Contact Form WordPress plugin before version 3.4.34.
4
What is the CVE description for CVE-2021-24165?
CVE-2021-24165 is a vulnerability in the Ninja Forms Contact Form WordPress plugin that allows for open redirect due to the use of a user supplied redirect parameter without proper protection.
5
How can I fix CVE-2021-24165?
To fix CVE-2021-24165, update the Ninja Forms Contact Form WordPress plugin to version 3.4.34 or later.