Ninja Forms <= 3.6.25 - Denial of Service via Large Form Submissions
2023-07-07 00:00
PetiteMaisStrategic Overview
StatusPatched in 3.6.26
Affected PluginNinja Forms – The Contact Form Builder That Grows With You
Affected Version
<= 3.6.25CVSS5.3Medium
CVE
CVE-2023-35909Vulnerability Overview
The Ninja Forms plugin for WordPress is vulnerable to denial of service in versions up to, and including, 3.6.25. This is due to insufficient controls on form submissions. This makes it possible for unauthenticated attackers to craft form submissions with excessive extra data that may exceed the capacity of the database and prevent further requests from being successful while the submission is processing.
Technical Analysis
REMEDIATION: Update to version 3.6.26, or a newer patched version --- IDENTIFIER: CWE-400 (Uncontrolled Resource Consumption) The product does not properly control the allocation and maintenance of a limited resource.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C