CVE · Critical

CVE-2024-37934 — Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.8.5

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-37934 Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.8.5 Improper Control of Generation of Code ('Code Injection') Critical 9.8 < 3.8.5 3.8.5 2024-07-04

CVE-2024-37934

The Ninja Forms plugin for WordPress contains a vulnerability that allows authenticated users with subscriber-level access or higher to execute arbitrary shortcodes. This is due to a failure to properly validate user input before running the do_shortcode function, which can be exploited to execute malicious shortcodes.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.