Description
WordPress Plugin Ninja Forms Contact Form-The Drag and Drop Form Builder for WordPress is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently preview un-published forms by injecting arbitrary shortcodes. WordPress Plugin Ninja Forms Contact Form-The Drag and Drop Form Builder for WordPress version 3.0.30 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 3.0.31 or latest
References
Related Vulnerabilities
WordPress Plugin Facebook-this Spam Links Injection (2.5)
WordPress Plugin Daily Prayer Time Cross-Site Request Forgery (2023.03.08)
WordPress Plugin WTI Like Post SQL Injection (1.4.2)
WordPress Plugin FlightLog SQL Injection (3.0.2)
WordPress Plugin Resume Submissions & Job Postings Arbitrary File Upload (2.5.3)