Ninja Forms <= 3.6.25 - Denial of Service via Large Form Submissions

2023-07-07 00:00
PetiteMais

Strategic Overview

Vulnerability Overview

The Ninja Forms plugin for WordPress is vulnerable to denial of service in versions up to, and including, 3.6.25. This is due to insufficient controls on form submissions. This makes it possible for unauthenticated attackers to craft form submissions with excessive extra data that may exceed the capacity of the database and prevent further requests from being successful while the submission is processing.

Technical Analysis

REMEDIATION: Update to version 3.6.26, or a newer patched version --- IDENTIFIER: CWE-400 (Uncontrolled Resource Consumption) The product does not properly control the allocation and maintenance of a limited resource.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C