Ninja Forms Contact Form <= 3.4.24.1 - Cross-Site Request Forgery leading to Stored Cross-Site Scripting
2020-04-28 00:00
RamStrategic Overview
StatusPatched in 3.4.24.2
Affected PluginNinja Forms – The Contact Form Builder That Grows With You
Affected Version
< 3.4.24.2CVSS6.1Medium
CVE
CVE-2020-12462Vulnerability Overview
The Ninja Forms plugin before 3.4.24.2 for WordPress allows CSRF with resultant XSS.
Technical Analysis
REMEDIATION: Update to version 3.4.24.2, or a newer patched version --- IDENTIFIER: CWE-352 (Cross-Site Request Forgery (CSRF)) The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C