vendor:
Ninja Forms
by:
Mehran Seifalinia
6.1
CVSS
MEDIUM
Reflected XSS
79
CWE
Product Name: Ninja Forms
Affected Version From: 3.6.25
Affected Version To: 3.6.25
Patch Exists: NO
Related CWE: CVE-2023-37979
CPE: a:ninja_forms_project:ninja_forms:3.6.25
Platforms Tested: Windows 10
2023
WordPress Plugin Ninja Forms 3.6.25 – Reflected XSS (Authenticated)
This exploit allows an authenticated user to execute arbitrary JavaScript code on the target website by submitting a crafted form template.
Mitigation:
Update to a non-vulnerable version of the plugin.