Description
The Ninja Forms WordPress plugin is vulnerable to arbitrary email sending via the trigger_email_action function found in the ~/includes/Routes/Submissions.php file, in versions up to and including 3.5.7. This allows authenticated attackers to send arbitrary emails from the affected server via the /ninja-forms-submissions/email-action REST API which can be used to socially engineer victims.
No analysis available yet.
Remediation
Vendor Solution
Update to version 3.5.8 or newer.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-21298 | The Ninja Forms WordPress plugin is vulnerable to arbitrary email sending via the trigger_email_action function found in the ~/includes/Routes/Submissions.php file, in versions up to and including 3.5.7. This allows authenticated attackers to send arbitrary emails from the affected server via the /ninja-forms-submissions/email-action REST API which can be used to socially engineer victims. |
References
History
Mon, 31 Mar 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 16 Sep 2024 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Ninja Forms <= 3.5.7 Unprotected REST-API to Email Injection | Ninja Forms <= 3.5.7 Unprotected REST-API to Email Injection |
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2025-03-31T18:20:03.844Z
Reserved: 2021-06-10T00:00:00.000Z
Link: CVE-2021-34648
Updated: 2024-08-04T00:19:47.576Z
Status : Modified
Published: 2021-09-22T18:15:11.990
Modified: 2024-11-21T06:10:53.360
Link: CVE-2021-34648
No data.
OpenCVE Enrichment
No data.
EUVD