CVE-2023-1835

CVSS 3.1 Score 6.1 of 10 (medium)

Details

Published May 15, 2023
Updated: Jan 14, 2025

Summary

CVE-2023-1835 is a Reflected Cross-Site Scripting (XSS) vulnerability affecting the Ninja Forms Contact Form plugin for WordPress before version 3.6.22. The issue stems from an lack of proper input escaping. This weakness allows an attacker to inject malicious scripts into an admin page, potentially exploiting high-privilege user accounts, such as administrators, leading to unintended functionality and potential data breaches.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Ninjaforms Ninja Forms
  • Ninja Forms

Affected Vendors

  • Ninjaforms