CVE · Medium

CVE-2018-19796 — Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.3.19.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2018-19796 Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.3.19.1 URL Redirection to Untrusted Site ('Open Redirect') Medium 6.1 < 3.3.19.1 3.3.19.1 2018-12-01

CVE-2018-19796

A vulnerability exists in the Ninja Forms plugin for WordPress, specifically in the step-processing.php file, where an attacker can manipulate the redirect parameter to trick users into visiting a malicious website. This issue allows remote attackers to redirect users through the plugin's submissions download page.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.