CVE · High

CVE-2024-39628 — Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.8.7

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-39628 Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.8.7 Cross-Site Request Forgery (CSRF) High 8.8 < 3.8.7 3.8.7 2024-07-24

CVE-2024-39628

The Ninja Forms plugin for WordPress is susceptible to a Cross-Site Request Forgery attack in versions up to 3.8.6. This vulnerability arises from inadequate validation of a security token in the submit_listener function, allowing unauthorized attackers to manipulate license information by tricking an administrator into taking a specific action, such as clicking on a malicious link.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.