CVE · Medium

CVE-2023-36505 — Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.6.25

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-36505 Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.6.25 Improper Input Validation Medium 6.8 < 3.6.25 3.6.25 2023-06-22

CVE-2023-36505

The Ninja Forms plugin for WordPress has a vulnerability in versions up to 3.6.24 that allows an authenticated administrator to delete any file on the server. This is because the plugin does not properly limit the file path that can be used for deletion, making it possible to target sensitive files such as wp-config.php. If an attacker deletes this file, they may be able to gain control over the site's database and potentially execute arbitrary code on the server.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.