First published: Wed Sep 22 2021(Updated: )
The Ninja Forms WordPress plugin is vulnerable to arbitrary email sending via the trigger_email_action function found in the ~/includes/Routes/Submissions.php file, in versions up to and including 3.5.7. This allows authenticated attackers to send arbitrary emails from the affected server via the /ninja-forms-submissions/email-action REST API which can be used to socially engineer victims.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ninja Forms | <=3.5.7 |
Update to version 3.5.8 or newer.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-34648 is a vulnerability in the Ninja Forms WordPress plugin that allows authenticated attackers to send arbitrary emails from the affected server.
CVE-2021-34648 has a severity rating of 4.3 out of 10.
CVE-2021-34648 affects the Ninja Forms plugin versions up to and including 3.5.7.
Attackers can exploit CVE-2021-34648 by using the trigger_email_action function in the ~/includes/Routes/Submissions.php file to send arbitrary emails.
Yes, a fix for CVE-2021-34648 is available. It is recommended to update the Ninja Forms plugin to a version beyond 3.5.7 to mitigate the vulnerability.