CVE-2021-34647: Ninja Forms <= 3.5.7 Sensitive Information Disclosure
The Ninja Forms WordPress plugin is vulnerable to sensitive information disclosure via the bulkexportsubmissions function found in the ~/includes/Routes/Submissions.php file, in versions up to and including 3.5.7. This allows authenticated attackers to export all Ninja Forms submissions data via the /ninja-forms-submissions/export REST API which can include personally identifiable information.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID of this Ninja Forms WordPress plugin vulnerability?
The vulnerability ID is CVE-2021-34647.
What is the severity of CVE-2021-34647?
The severity of CVE-2021-34647 is medium with a severity value of 6.5.
How can an attacker exploit the vulnerability in the Ninja Forms plugin?
An attacker can exploit the vulnerability by using the bulk_export_submissions function in the ~/includes/Routes/Submissions.php file to disclose sensitive information.
Which versions of the Ninja Forms plugin are affected by CVE-2021-34647?
Versions up to and including 3.5.7 of the Ninja Forms plugin are affected by CVE-2021-34647.
Is there a fix available for the vulnerability?
Yes, a fix for the vulnerability is available. It is recommended to update to a version of the Ninja Forms plugin that is higher than 3.5.7.