CVE · High

CVE-2021-24163 — Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.4.34

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2021-24163 Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.4.34 Exposure of Sensitive Information to an Unauthorized Actor High 8.8 < 3.4.34 3.4.34 2021-02-16

CVE-2021-24163

A vulnerability was found in the AJAX action for sending and installing the SendWP plugin, where a capability check and nonce protection were missing. This allowed low-level users to install and activate the plugin without proper authorization, and also obtain the client_secret key required for the SendWP connection. As a result, unauthorized users could potentially exploit this weakness to install the plugin and access sensitive information.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.