CVE · Medium

CVE-2021-24165 — Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.4.34

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2021-24165 Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.4.34 URL Redirection to Untrusted Site ('Open Redirect') Medium 6.1 < 3.4.34 3.4.34 2021-02-16

CVE-2021-24165

The Ninja Forms Contact Form WordPress plugin, versions prior to 3.4.34, contained a vulnerability that allowed attackers to redirect users to malicious websites. This was due to the plugin's use of a user-supplied redirect parameter in its AJAX action, which was not properly validated or sanitized, enabling potential open redirect attacks.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.