CVE · Medium

CVE-2024-12238 — Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.8.23

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-12238 Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.8.23 Improper Control of Generation of Code ('Code Injection') Medium 6.3 < 3.8.23 3.8.23 2024-12-28

CVE-2024-12238

The Ninja Forms plugin for WordPress has a security flaw that allows attackers with a Subscriber-level account or higher to execute arbitrary shortcodes. This is because the plugin doesn't properly check the value of a user-controlled input before running the shortcode, making it vulnerable to exploitation.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.