WordPress 插件 “Ninja Forms – The Contact Form Builder That Grows With You” 存在存储型跨站脚本(Stored Cross-Site Scripting, XSS)漏洞。该漏洞出现在 3.15.4 及更早版本中,原因在于对段落文本(RTE,即富文本编辑器)字段提交内容的输入净化和输出转义处理不足。攻击者无需认证即可在页面中注入任意 Web 脚本,当用户访问被注入的页面时,这些脚本将会执行。需要注意的是,该漏洞仅在目标“段落文本”字段启用了富文本编
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| kstover | Ninja Forms – Contact Form Builder with Calculators, Quizzes, Signatures & AI Form Builder | ≤ 3.15.4 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| kstover | Ninja Forms – Contact Form Builder with Calculators, Quizzes, Signatures & AI Form Builder | 0 ~ 3.15.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet