CVE-2023-1835
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Published May 15, 2023
Updated: Jan 14, 2025
Summary
CVE-2023-1835 is a Reflected Cross-Site Scripting (XSS) vulnerability affecting the Ninja Forms Contact Form plugin for WordPress before version 3.6.22. The issue stems from an lack of proper input escaping. This weakness allows an attacker to inject malicious scripts into an admin page, potentially exploiting high-privilege user accounts, such as administrators, leading to unintended functionality and potential data breaches.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Ninjaforms Ninja Forms
- Ninja Forms
Affected Vendors
- Ninjaforms