CVE-2021-24164 Information

Description

In the Ninja Forms Contact Form WordPress plugin before 3.4.34.1 low-level users such as subscribers were able to trigger the action wp_ajax_nf_oauth and retrieve the connection url needed to establish a connection. They could also retrieve the client_id for an already established OAuth connection.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Reference

https://wpscan.com/vulnerability/dfa32afa-c6de-4237-a9f2-709843dcda89 https://www.wordfence.com/blog/2021/02/one-million-sites-affected-four-severe-vulnerabilities-patched-in-ninja-forms/ In the Ninja Forms Contact Form WordPress plugin before 3.4.34.1 low-level users such as subscribers were able to trigger the action wp_ajax_nf_oauth and retrieve the connection url needed to establish a connection. They could also retrieve the client_id for an already established OAuth connection.

Attack Complexity

LOW

Privileges Required

LOW

User Interaction Required

LOW

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

LOW

Availability Impact

NONE

Base Score

NONE

Base Severity

4.3

Share on: