CVE Database /
CVE-2023-36505
CVE · Medium
CVE-2023-36505 — Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.6.25
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2023-36505
|
Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.6.25 |
Improper Input Validation |
Medium
6.8
|
< 3.6.25
|
3.6.25 |
2023-06-22 |
—
|
CVE-2023-36505
The Ninja Forms plugin for WordPress has a vulnerability in versions up to 3.6.24 that allows an authenticated administrator to delete any file on the server. This is because the plugin does not properly limit the file path that can be used for deletion, making it possible to target sensitive files such as wp-config.php. If an attacker deletes this file, they may be able to gain control over the site's database and potentially execute arbitrary code on the server.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings