CVE-2023-38386: WordPress Ninja Forms plugin <= 3.6.25 - Contributor+ Broken Access Control vulnerability
Published Jun 19, 2024
·Updated
Missing Authorization vulnerability in Saturday Drive Ninja Forms.This issue affects Ninja Forms: from n/a through 3.6.25.
Affected Software
3 affected components
Saturday Drive Ninja Forms<=3.6.25
WordPress Ninja Forms<=3.6.25
NinjaForms Ninja Forms Wordpress<3.6.26
Remediation
Information
Update to 3.6.26 or a higher version.
Event History
Jun 19, 2024
CVE Published
via MITRE·01:06 PM
Data Sourced
via MITRE·01:06 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-38386?
CVE-2023-38386 has been classified as a moderate severity vulnerability due to its missing authorization issue.
2
How do I fix CVE-2023-38386?
To fix CVE-2023-38386, update Ninja Forms to version 3.6.26 or later.
3
What versions are affected by CVE-2023-38386?
CVE-2023-38386 affects Ninja Forms versions up to and including 3.6.25.
4
What type of vulnerability is CVE-2023-38386?
CVE-2023-38386 is a broken access control vulnerability.
5
Who is impacted by CVE-2023-38386?
Users of Saturday Drive Ninja Forms versions up to 3.6.25 are impacted by CVE-2023-38386.