nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-24164 CVE-2021-24164
MEDIUM
Ninja Forms < 3.4.34.1 - Authenticated OAuth Connection Key Disclosure
Record summary
CVE-2021-24164 has a selected CVSS score of 4.3 (medium).
Description
In the Ninja Forms Contact Form WordPress plugin before 3.4.34.1, low-level users, such as subscribers, were able to trigger the action, wp_ajax_nf_oauth, and retrieve the connection url needed to establish a connection. They could also retrieve the client_id for an already established OAuth connection.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jan 18, 2023 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress | CVE List | 3.4.34.1 to < 3.4.34.1 | affected |
ninja_formsBrowse ninjaforms / ninja_forms | VulnCheck | Version data not supplied | |
References
3wpscan.comConfirmation
https://wpscan.com/vulnerability/dfa32afa-c6de-4237-a9f2-709843dcda89 wordfence.com
https://www.wordfence.com/blog/2021/02/one-million-sites-affected-four-severe-vulnerabilities-patched-in-ninja-forms