Input validation error in Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress - CVE-2021-34648
Published: September 24, 2021
Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress
The WP Ninjas
Description
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to insufficient validation of user-supplied input in the "trigger_email_action" function in the ~/includes/Routes/Submissions.php file. A remote authenticated attacker can use a specially crafted email to socially engineer victims.