CVE-2024-2108: Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress <= 3.8.0 - Authenticated (Author+) Stored Cross-Site Scripting
The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an image title embedded into a form in all versions up to, and including, 3.8.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-2108?
CVE-2024-2108 has a moderate severity rating due to the potential for Stored Cross-Site Scripting attacks.
How do I fix CVE-2024-2108?
To fix CVE-2024-2108, update the Ninja Forms plugin to version 3.8.1 or later, which includes the necessary security patches.
What are the impacted versions of the Ninja Forms plugin for CVE-2024-2108?
All versions of the Ninja Forms plugin up to and including 3.8.0 are impacted by CVE-2024-2108.
How can CVE-2024-2108 affect my website?
CVE-2024-2108 can lead to malicious scripts being executed on your website, potentially compromising user data and site integrity.
What kind of attack can be executed using CVE-2024-2108?
CVE-2024-2108 allows attackers to perform Stored Cross-Site Scripting (XSS) attacks by exploiting insufficient input sanitization.