CVE-2024-7354: Ninja Forms 3.8.6-3.8.10 - Reflected XSS
Published Sep 2, 2024
·Updated
The Ninja Forms WordPress plugin before 3.8.11 does not escape an URL before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
Affected Software
1 affected component
NinjaForms Ninja Forms Wordpress>=3.8.6<3.8.11
Event History
Sep 2, 2024
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·08:15 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2024-7354?
CVE-2024-7354 has been designated a high severity vulnerability due to its potential impact on high privilege users.
2
How do I fix CVE-2024-7354?
To fix CVE-2024-7354, update the Ninja Forms WordPress plugin to version 3.8.11 or later.
3
What type of vulnerability is CVE-2024-7354?
CVE-2024-7354 is classified as a Reflected Cross-Site Scripting vulnerability.
4
Who is affected by CVE-2024-7354?
CVE-2024-7354 primarily affects high privilege users, such as administrators of WordPress sites using the vulnerable plugin.
5
What versions of the Ninja Forms plugin are impacted by CVE-2024-7354?
Ninja Forms versions before 3.8.11, specifically between versions 3.8.6 and 3.8.10, are impacted by CVE-2024-7354.