CVE-2021-36827: WordPress Ninja Forms Contact Form plugin <= 3.6.9 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability
Published Jun 16, 2022
·Updated
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Saturday Drive's Ninja Forms Contact Form plugin <= 3.6.9 at WordPress via "label".
Affected Software
1 affected component
NinjaForms Ninja Forms Wordpress<=3.6.9
Remediation
Information
Update to 3.6.10 or higher version.
Event History
Jun 16, 2022
CVE Published
via MITRE·05:11 PM
Data Sourced
via MITRE·05:11 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2021-36827.
2
What is the title of the vulnerability?
The title of the vulnerability is 'Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Saturday Drive's Ninja Forms Contact Form plugin <= 3.6.9 at WordPress via "label".'
3
What is the affected software?
The affected software is Ninja Forms Contact Form plugin version 3.6.9 or earlier at WordPress.
4
What is the severity of the vulnerability?
The severity of the vulnerability is medium, with a CVSS score of 4.8.
5
How can the vulnerability be exploited?
The vulnerability can be exploited by an authenticated admin user who can inject malicious code through the 'label' field in Ninja Forms Contact Form.