CVE-2021-24165
Ninja Forms < 3.4.34 - Administrator Open Redirect
Record summary
CVE-2021-24165 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
In the Ninja Forms Contact Form WordPress plugin before 3.4.34, the wp_ajax_nf_oauth_connect AJAX action was vulnerable to open redirect due to the use of a user supplied redirect parameter and no protection in place.
Exploitation context
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress | CVE List | 3.4.34 to < 3.4.34 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMWordPress Ninja Forms <3.4.34 - Open RedirectCVSS 6.1
WordPress Ninja Forms plugin before 3.4.34 contains an open redirect vulnerability via the wp_ajax_nf_oauth_connect AJAX action, due to the use of a user-supplied redirect parameter and no protection in place. An attacker can redirect a user to a malicious site and possibly obtain sensitive information, modify data, and/or execute unauthorized operations.
Impact
An attacker can exploit this vulnerability to redirect users to malicious websites, leading to phishing attacks or the installation of malware.
Remediation
Update to the latest version of the Ninja Forms plugin (3.4.34 or higher) to fix the open redirect vulnerability.
Source: ProjectDiscovery