CVE-2021-24166: Ninja Forms < 3.4.34 - CSRF to OAuth Service Disconnection
Published Apr 5, 2021
·Updated
The wpajaxnfoauthdisconnect from the Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress WordPress plugin before 3.4.34 had no nonce protection making it possible for attackers to craft a request to disconnect a site's OAuth connection.
Affected Software
1 affected component
NinjaForms Ninja Forms Wordpress<3.4.34
Event History
Apr 5, 2021
CVE Published
via MITRE·06:27 PM
Data Sourced
via MITRE·06:27 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2021-24166?
CVE-2021-24166 is a vulnerability in the Ninja Forms Contact Form WordPress plugin before version 3.4.34.
2
How severe is CVE-2021-24166?
CVE-2021-24166 has a severity score of 5.4 (Medium).
3
What is the affected software?
The affected software is the Ninja Forms Contact Form WordPress plugin version up to and excluding 3.4.34.
4
What is the impact of CVE-2021-24166?
CVE-2021-24166 allows attackers to craft a request to disconnect a site's OAuth connection.
5
How can I fix CVE-2021-24166?
To fix CVE-2021-24166, update the Ninja Forms Contact Form WordPress plugin to version 3.4.34 or newer.