Record summary

CVE-2018-19287 has a selected CVSS score of 6.1 (medium); EIP currently links 1 catalogued exploit and 1 Nuclei template.

Description

XSS in the Ninja Forms plugin before 3.3.18 for WordPress allows Remote Attackers to execute JavaScript via the includes/Admin/Menus/Submissions.php (aka submissions page) begin_date, end_date, or form_id parameter.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1
Nuclei templates
1

Proofs of concept

1

Catalogued exploits

ExploitDBWordPress Plugin Ninja Forms 3.3.17 - Cross-Site ScriptingExploitDB exploitby MTKNot analyzed1 file
ExploitDB

PoC details

Nuclei templates

1
ProjectDiscoveryMEDIUMWordPress Ninja Forms <3.3.18 - Cross-Site ScriptingCVSS 6.1

WordPress Ninja Forms plugin before 3.3.18 contains a cross-site scripting vulnerability. An attacker can inject arbitrary script in includes/Admin/Menus/Submissions.php via the begin_date, end_date, or form_id parameters. This can allow an attacker to steal cookie-based authentication credentials and launch other attacks.

Impact

Successful exploitation of this vulnerability could allow an attacker to inject malicious scripts into web pages viewed by users, leading to potential data theft, session hijacking, or defacement of the affected website.

Remediation

Upgrade to the latest version of the Ninja Forms plugin (3.3.18 or higher) to mitigate this vulnerability.

WeaknessesCWE-79
Authorstheamanrawat
Template tagscvecve2018wp-pluginwpxssauthenticatedwpscanedbninja-formswordpressninjaformavuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:ninjaforma:ninja_forms:*:*:*:*:*:wordpress:*:*
Shodan: http.html:/wp-content/plugins/ninja-forms/
FOFA: body=/wp-content/plugins/ninja-forms/

Source: ProjectDiscovery

References

4