CVE · Medium

CVE-2024-3866 — Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.8.16

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-3866 Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.8.16 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 3.8.16 3.8.16 2024-09-24

CVE-2024-3866

The Ninja Forms Contact Form plugin for WordPress contains a vulnerability that allows unauthenticated attackers to inject arbitrary web scripts into pages, by exploiting a reflected self-based cross-site scripting issue through the 'Referer' header. This can occur when a user clicks on a malicious link, provided that the targeted form is in maintenance mode, a state that is automatically triggered during a required plugin update. However, the maintenance mode is only temporarily enabled during the update process, limiting the attack window.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.