Ninja Forms <= 3.4.34 - Authenticated OAuth Connection Key Disclosure
2021-02-16 00:00
Chloe ChamberlandStrategic Overview
StatusPatched in 3.4.34.1
Affected PluginNinja Forms – The Contact Form Builder That Grows With You
Affected Version
< 3.4.34.1CVSS4.3Medium
CVE
CVE-2021-24164Vulnerability Overview
In the Ninja Forms Contact Form WordPress plugin before 3.4.34.1, low-level users, such as subscribers, were able to trigger the action, wp_ajax_nf_oauth, and retrieve the connection url needed to establish a connection. They could also retrieve the client_id for an already established OAuth connection.
Technical Analysis
REMEDIATION: Update to version 3.4.34.1, or a newer patched version --- IDENTIFIER: CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C