CVE-2023-1835: Ninja Forms < 3.6.22 - Reflected XSS
The Ninja Forms Contact Form WordPress plugin before 3.6.22 does not properly escape user input before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2023-1835.
What is the severity level of CVE-2023-1835?
The severity level of CVE-2023-1835 is medium with a CVSS score of 6.1.
What is the affected software?
The affected software is Ninja Forms Contact Form WordPress plugin version up to and including 3.6.22.
What is the potential impact of this vulnerability?
The potential impact of this vulnerability is a Reflected Cross-Site Scripting (XSS) which could be used against high privilege users such as admin.
How can I fix CVE-2023-1835?
To fix CVE-2023-1835, upgrade to the latest version of the Ninja Forms Contact Form WordPress plugin (version 3.6.23 or higher) which contains a patch for this issue.