First published: Thu Jun 16 2022(Updated: )
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Saturday Drive's Ninja Forms Contact Form plugin <= 3.6.9 at WordPress via "label".
Credit: audit@patchstack.com audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ninja Forms | <=3.6.9 |
Update to 3.6.10 or higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-36827.
The title of the vulnerability is 'Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Saturday Drive's Ninja Forms Contact Form plugin <= 3.6.9 at WordPress via "label".'
The affected software is Ninja Forms Contact Form plugin version 3.6.9 or earlier at WordPress.
The severity of the vulnerability is medium, with a CVSS score of 4.8.
The vulnerability can be exploited by an authenticated admin user who can inject malicious code through the 'label' field in Ninja Forms Contact Form.