CVE-2021-24164
- EPSS 0.17%
- Veröffentlicht 05.04.2021 19:15:15
- Zuletzt bearbeitet 21.11.2024 05:52:30
In the Ninja Forms Contact Form WordPress plugin before 3.4.34.1, low-level users, such as subscribers, were able to trigger the action, wp_ajax_nf_oauth, and retrieve the connection url needed to establish a connection. They could also retrieve the ...
CVE-2021-24165
- EPSS 1.17%
- Veröffentlicht 05.04.2021 19:15:15
- Zuletzt bearbeitet 21.11.2024 05:52:30
In the Ninja Forms Contact Form WordPress plugin before 3.4.34, the wp_ajax_nf_oauth_connect AJAX action was vulnerable to open redirect due to the use of a user supplied redirect parameter and no protection in place.
CVE-2021-24166
- EPSS 0.09%
- Veröffentlicht 05.04.2021 19:15:15
- Zuletzt bearbeitet 21.11.2024 05:52:30
The wp_ajax_nf_oauth_disconnect from the Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress WordPress plugin before 3.4.34 had no nonce protection making it possible for attackers to craft a request to disconnect a site's OAuth c...
CVE-2020-36175
- EPSS 0.19%
- Veröffentlicht 06.01.2021 15:15:15
- Zuletzt bearbeitet 21.11.2024 05:28:53
The Ninja Forms plugin before 3.4.27.1 for WordPress allows attackers to bypass validation via the email field.
CVE-2020-36174
- EPSS 0.14%
- Veröffentlicht 06.01.2021 15:15:15
- Zuletzt bearbeitet 21.11.2024 05:28:53
The Ninja Forms plugin before 3.4.27.1 for WordPress allows CSRF via services integration.
CVE-2020-36173
- EPSS 0.19%
- Veröffentlicht 06.01.2021 15:15:15
- Zuletzt bearbeitet 21.11.2024 05:28:53
The Ninja Forms plugin before 3.4.28 for WordPress lacks escaping for submissions-table fields.
CVE-2020-12462
- EPSS 0.26%
- Veröffentlicht 29.04.2020 17:15:12
- Zuletzt bearbeitet 21.11.2024 04:59:45
The ninja-forms plugin before 3.4.24.2 for WordPress allows CSRF with resultant XSS.
CVE-2020-8594
- EPSS 0.86%
- Veröffentlicht 14.02.2020 20:15:09
- Zuletzt bearbeitet 21.11.2024 05:39:05
The Ninja Forms plugin 3.4.22 for WordPress has Multiple Stored XSS vulnerabilities via ninja_forms[recaptcha_site_key], ninja_forms[recaptcha_secret_key], ninja_forms[recaptcha_lang], or ninja_forms[date_format].
CVE-2018-20981
- EPSS 0.6%
- Veröffentlicht 22.08.2019 13:15:12
- Zuletzt bearbeitet 21.11.2024 04:02:37
The ninja-forms plugin before 3.3.9 for WordPress has insufficient restrictions on submission-data retrieval during Export Personal Data requests.
CVE-2018-20980
- EPSS 0.28%
- Veröffentlicht 22.08.2019 13:15:12
- Zuletzt bearbeitet 21.11.2024 04:02:37
The ninja-forms plugin before 3.2.15 for WordPress has parameter tampering.