CVE-2023-4109: Ninja Forms < 3.6.26 - Admin+ Stored HTML Injection
Published Aug 30, 2023
·Updated
The Ninja Forms WordPress Ninja Forms Contact Form WordPress plugin before 3.6.26 was affected by a HTML Injection security vulnerability.
Affected Software
1 affected component
NinjaForms Ninja Forms Contact Form Wordpress<3.6.26
Event History
Aug 30, 2023
CVE Published
via MITRE·02:22 PM
Data Sourced
via MITRE·02:22 PM
DescriptionWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is CVE-2023-4109?
CVE-2023-4109 is a HTML Injection security vulnerability in the Ninja Forms Contact Form plugin before version 3.6.26 for WordPress.
2
How does CVE-2023-4109 affect Ninja Forms Contact Form?
CVE-2023-4109 affects the Ninja Forms Contact Form plugin before version 3.6.26, allowing for HTML Injection attacks.
3
How severe is CVE-2023-4109?
CVE-2023-4109 has a severity rating of medium with a CVSS score of 4.8.
4
How do I fix CVE-2023-4109?
To fix CVE-2023-4109, update the Ninja Forms Contact Form plugin to version 3.6.26 or later.
5
Where can I find more information about CVE-2023-4109?
For more information about CVE-2023-4109, you can visit the following reference: https://wpscan.com/vulnerability/558e06ab-704b-4bb1-ba7f-b5f6bbbd68d9