nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-34648 CVE-2021-34648
MEDIUM
Ninja Forms <= 3.5.7 Unprotected REST-API to Email Injection
Record summary
CVE-2021-34648 has a selected CVSS score of 6.4 (medium).
Description
The Ninja Forms WordPress plugin is vulnerable to arbitrary email sending via the trigger_email_action function found in the ~/includes/Routes/Submissions.php file, in versions up to and including 3.5.7. This allows authenticated attackers to send arbitrary emails from the affected server via the /ninja-forms-submissions/email-action REST API which can be used to socially engineer victims.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Sep 22, 2021 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 31, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Ninja FormsBrowse Saturday Drive / Ninja Forms | CVE List | 3.5.7 to ≤ 3.5.7 | affected |
ninja_formsBrowse ninjaforms / ninja_forms | VulnCheck | Version data not supplied | |
References
3plugins.trac.wordpress.org
https://plugins.trac.wordpress.org/browser/ninja-forms/trunk/includes/Routes/Submissions.php?rev=2543837 wordfence.com
https://www.wordfence.com/blog/2021/09/recently-patched-vulnerabilities-in-ninja-forms-plugin-affects-over-1-million-site-owners