CVE-2024-2113 is a Cross-Site Request Forgery (CSRF) vulnerability affecting all versions up to and including 3.8.0 of the Ninja Forms Contact Form plugin for WordPress. This flaw stems from missing or incorrect nonce validation on the nf_download_all_subs AJAX action. An unauthenticated attacker could exploit this by tricking a site administrator into clicking a malicious link, leading to the export of form submissions to a publicly accessible location. Rated 4.3 MEDIUM on the CVSS scale, this vulnerability has low complexity but requires user interaction and has a low impact on confidentiality. There is currently no evidence of active exploitation, public exploit code, or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.8.1CPE matchmatch criteria | cpe:2.3:a:ninjaforms:ninja_forms:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.