The Ninja Forms WordPress plugin is vulnerable to arbitrary email sending via the trigger_email_action function found in the ~/includes/Routes/Submissions.php file, in versions up to and including 3.5.7. This allows authenticated attackers to send arbitrary emails from the affected server via the /ninja-forms-submissions/email-action REST API which can be used to socially engineer victims.
Fixes

Solution

Update to version 3.5.8 or newer.


Workaround

No workaround given by the vendor.

History

Mon, 31 Mar 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 16 Sep 2024 23:15:00 +0000

Type Values Removed Values Added
Title Ninja Forms <= 3.5.7 Unprotected REST-API to Email Injection Ninja Forms <= 3.5.7 Unprotected REST-API to Email Injection

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2025-03-31T18:20:03.844Z

Reserved: 2021-06-10T00:00:00.000Z

Link: CVE-2021-34648

cve-icon Vulnrichment

Updated: 2024-08-04T00:19:47.576Z

cve-icon NVD

Status : Modified

Published: 2021-09-22T18:15:11.990

Modified: 2024-11-21T06:10:53.360

Link: CVE-2021-34648

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.