Impact
Unauthenticated Cross Site Scripting (XSS) is present in Ninja Forms File Uploads Extension versions up to 3.3.26. The flaw allows an attacker to inject malicious scripts that are rendered in the browser of any visitor to pages that use the vulnerable form. By executing arbitrary JavaScript, an attacker can hijack user sessions, steal credentials, deface the site, or redirect traffic to malicious destinations. The weakness is categorized as CWE‑79, which relates to improper input validation of user‑supplied data leading to dangerous code execution on a client side.
Affected Systems
WordPress sites that use the Ninja Forms File Uploads Extension plugin from Saturday Drive. The vulnerability affects all installations using plugin version 3.3.26 or earlier; any newer release is not affected.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity for an unauthenticated vulnerability. The EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog, but the lack of those metrics does not diminish the risk because the flaw can be exploited remotely by anyone who can submit data to the vulnerable form. An attacker requires no authentication and can simply craft a request that contains malicious script, which is then delivered to all site visitors. Consequently, the potential impact on confidentiality and integrity is significant, and the overall risk to affected WordPress installations is high.
OpenCVE Enrichment