CVE-2023-36505: WordPress Ninja Forms Plugin <= 3.6.24 is vulnerable to Arbitrary File Deletion
Published Apr 17, 2024
·Updated
Improper Input Validation vulnerability in Saturday Drive Ninja Forms Contact Form.This issue affects Ninja Forms Contact Form : from n/a through 3.6.24.
Affected Software
3 affected components
NinjaForms Ninja Forms Wordpress<3.6.25
Saturday Drive Ninja Forms<=3.6.24
WordPress Ninja Forms Plugin<=3.6.24
Remediation
Information
Update to 3.6.25 or a higher version.
Event History
Apr 17, 2024
CVE Published
via MITRE·09:09 AM
Data Sourced
via MITRE·09:09 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeaknessAffected Software
Jul 25, 57260
Event
via NVD·12:51 PM
Frequently Asked Questions
1
What is the severity of CVE-2023-36505?
CVE-2023-36505 has a high severity due to improper input validation that can lead to arbitrary file deletion.
2
How do I fix CVE-2023-36505?
To fix CVE-2023-36505, update the Ninja Forms Contact Form plugin to version 3.6.25 or later.
3
Which versions are affected by CVE-2023-36505?
Versions of Ninja Forms Contact Form from n/a through 3.6.24 are affected by CVE-2023-36505.
4
What is the risk associated with CVE-2023-36505?
The risk associated with CVE-2023-36505 includes potential unauthorized file deletion, which can compromise website integrity.
5
Who is impacted by CVE-2023-36505?
Users of Ninja Forms Contact Form versions up to 3.6.24 on WordPress are impacted by CVE-2023-36505.