Record summary

CVE-2021-24165 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

In the Ninja Forms Contact Form WordPress plugin before 3.4.34, the wp_ajax_nf_oauth_connect AJAX action was vulnerable to open redirect due to the use of a user supplied redirect parameter and no protection in place.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus

Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress

CVE List3.4.34 to < 3.4.34affected

Nuclei templates

1
ProjectDiscoveryMEDIUMWordPress Ninja Forms <3.4.34 - Open RedirectCVSS 6.1

WordPress Ninja Forms plugin before 3.4.34 contains an open redirect vulnerability via the wp_ajax_nf_oauth_connect AJAX action, due to the use of a user-supplied redirect parameter and no protection in place. An attacker can redirect a user to a malicious site and possibly obtain sensitive information, modify data, and/or execute unauthorized operations.

Impact

An attacker can exploit this vulnerability to redirect users to malicious websites, leading to phishing attacks or the installation of malware.

Remediation

Update to the latest version of the Ninja Forms plugin (3.4.34 or higher) to fix the open redirect vulnerability.

WeaknessesCWE-601
AuthorsdhiyaneshDk, daffainfo
Template tagscve2021cvewordpressredirectwp-pluginauthenticatedwpwpscanninjaformsvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:ninjaforms:ninja_forms:*:*:*:*:*:wordpress:*:*
Shodan: http.html:/wp-content/plugins/ninja-forms/
FOFA: body=/wp-content/plugins/ninja-forms/

Source: ProjectDiscovery

References

3