Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress <= 3.6.10 - Code Injection

2022-06-15 00:00
Anonymous

Strategic Overview

Status
Patched in 3.0.34.2
Affected Version3.0.34.1 – 3.6.10 · 7 branches
CVSS9.8Critical
CVEN/A
View all Ninja Forms – The Contact Form Builder That Grows With You vulnerabilities

Vulnerability Overview

The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to code injection in versions up to, and including 3.6.10 due to insufficient validation on Merge Tags that makes it possible to call arbitrary Ninja Form classes. This could lead to a variety of actions, however, one notable one is deserialization when the NF_Admin_Processes_ImportForm::startup method is called. On sites with a POP chain this could be used to achieve remote code execution in the worst possible scenarios.

Technical Analysis

REMEDIATION: Update to one of the following versions, or a newer patched version: 3.0.34.2, 3.1.10, 3.2.28, 3.3.21.4, 3.4.34.2, 3.5.8.4, 3.6.11 --- IDENTIFIER: CWE-94 (Improper Control of Generation of Code ('Code Injection')) The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C