First published: Mon Sep 02 2024(Updated: )
The Ninja Forms WordPress plugin before 3.8.11 does not escape an URL before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ninja Forms | >=3.8.6<3.8.11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-7354 has been designated a high severity vulnerability due to its potential impact on high privilege users.
To fix CVE-2024-7354, update the Ninja Forms WordPress plugin to version 3.8.11 or later.
CVE-2024-7354 is classified as a Reflected Cross-Site Scripting vulnerability.
CVE-2024-7354 primarily affects high privilege users, such as administrators of WordPress sites using the vulnerable plugin.
Ninja Forms versions before 3.8.11, specifically between versions 3.8.6 and 3.8.10, are impacted by CVE-2024-7354.