• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
multiple flaws found in ninja forms plugin leave 800,000 sites

Multiple Flaws Found in Ninja Forms Plugin Leave 800,000 Sites Vulnerable

You are here: Home / General Cyber Security News / Multiple Flaws Found in Ninja Forms Plugin Leave 800,000 Sites Vulnerable
July 31, 2023

Many security vulnerabilities have been disclosed in the Ninja Forms plugin for WordPress that could be exploited by danger actors to escalate privileges and steal delicate knowledge.

The flaws, tracked as CVE-2023-37979, CVE-2023-38386, and CVE-2023-38393, affect versions 3.6.25 and under, Patchstack explained in a report past 7 days. Ninja Types is set up on over 800,000 internet sites.

A temporary description of every of the vulnerabilities is below –

✔ Approved Seller From Our Partners
Mullvad VPN Discount

Protect your privacy by Mullvad VPN. Mullvad VPN is one of the famous brands in the security and privacy world. With Mullvad VPN you will not even be asked for your email address. No log policy, no data from you will be saved. Get your license key now from the official distributor of Mullvad with discount: SerialCart® (Limited Offer).

➤ Get Mullvad VPN with 12% Discount


  • CVE-2023-37979 (CVSS rating: 7.1) – A Article-dependent reflected cross-site scripting (XSS) flaw that could let any unauthenticated consumer to obtain privilege escalation on a goal WordPress web page by tricking privileged end users to pay a visit to a specifically crafted web page.
  • CVE-2023-38386 and CVE-2023-38393 – Broken access management flaws in the variety submissions export function that could allow a terrible actor with Subscriber and Contributor roles to export all Ninja Varieties submissions on a WordPress website.

End users of the plugin are advised to update to edition 3.6.26 to mitigate prospective threats.

Forthcoming WEBINARShield Against Insider Threats: Grasp SaaS Security Posture Administration

Fearful about insider threats? We have acquired you coated! Be a part of this webinar to discover functional approaches and the secrets of proactive security with SaaS Security Posture Management.

Join Nowadays

The disclosure arrives as Patchstack discovered a further mirrored XSS vulnerability flaw in the Freemius WordPress application growth kit (SDK) affecting variations prior to 2.5.10 (CVE-2023-33999) that could be exploited to get hold of elevated privileges.

Also found by the WordPress security business is a critical bug in the HT Mega plugin (CVE-2023-37999) existing in versions 2.2. and below that allows any unauthenticated person to escalate their privilege to that of any role on the WordPress site.

Found this posting fascinating? Abide by us on Twitter  and LinkedIn to read more special material we put up.


Some components of this post are sourced from:
thehackernews.com

Previous Post: «new android malware cherryblos utilizing ocr to steal sensitive data New Android Malware CherryBlos Utilizing OCR to Steal Sensitive Data
Next Post: Fruity Trojan Uses Deceptive Software Installers to Spread Remcos RAT fruity trojan uses deceptive software installers to spread remcos rat»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Zero-Click Agentic Browser Attack Can Delete Entire Google Drive Using Crafted Emails
  • Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patch
  • Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability
  • Intellexa Leaks Reveal Zero-Days and Ads-Based Vector for Predator Spyware Delivery
  • “Getting to Yes”: An Anti-Sales Guide for MSPs
  • CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems
  • JPCERT Confirms Active Command Injection Attacks on Array AG Gateways
  • Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China
  • ThreatsDay Bulletin: Wi-Fi Hack, npm Worm, DeFi Theft, Phishing Blasts— and 15 More Stories
  • 5 Threats That Reshaped Web Security This Year [2025]

Copyright © TheCyberSecurity.News, All Rights Reserved.