CVE-2021-34648: Ninja Forms <= 3.5.7 Unprotected REST-API to Email Injection
The Ninja Forms WordPress plugin is vulnerable to arbitrary email sending via the triggeremailaction function found in the ~/includes/Routes/Submissions.php file, in versions up to and including 3.5.7. This allows authenticated attackers to send arbitrary emails from the affected server via the /ninja-forms-submissions/email-action REST API which can be used to socially engineer victims.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2021-34648?
CVE-2021-34648 is a vulnerability in the Ninja Forms WordPress plugin that allows authenticated attackers to send arbitrary emails from the affected server.
How severe is CVE-2021-34648?
CVE-2021-34648 has a severity rating of 4.3 out of 10.
How does CVE-2021-34648 affect the Ninja Forms plugin?
CVE-2021-34648 affects the Ninja Forms plugin versions up to and including 3.5.7.
How can attackers exploit CVE-2021-34648?
Attackers can exploit CVE-2021-34648 by using the trigger_email_action function in the ~/includes/Routes/Submissions.php file to send arbitrary emails.
Is there a fix available for CVE-2021-34648?
Yes, a fix for CVE-2021-34648 is available. It is recommended to update the Ninja Forms plugin to a version beyond 3.5.7 to mitigate the vulnerability.