First published: Wed Aug 30 2023(Updated: )
The Ninja Forms WordPress Ninja Forms Contact Form WordPress plugin before 3.6.26 was affected by a HTML Injection security vulnerability.
Credit: contact@wpscan.com contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ninja Forms | <3.6.26 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-4109 is a HTML Injection security vulnerability in the Ninja Forms Contact Form plugin before version 3.6.26 for WordPress.
CVE-2023-4109 affects the Ninja Forms Contact Form plugin before version 3.6.26, allowing for HTML Injection attacks.
CVE-2023-4109 has a severity rating of medium with a CVSS score of 4.8.
To fix CVE-2023-4109, update the Ninja Forms Contact Form plugin to version 3.6.26 or later.
For more information about CVE-2023-4109, you can visit the following reference: https://wpscan.com/vulnerability/558e06ab-704b-4bb1-ba7f-b5f6bbbd68d9