The popular WordPress form builder plugin, Ninja Forms, has three vulnerabilities that could allow malicious users to gain privileges and steal personal data. It is important to improve the security of these vulnerabilities to protect users and their data.
See also: WordPress plugin gives hackers admin access to your site

Researchers at Patchstack discovered and disclosed three vulnerabilities in the code of the Saturday Drive plugin on June 22, 2023. These vulnerabilities impact NinjaForms versions 3.6.25 and earlier.
The developers released version 3.6.26 on July 4, 2023, with the aim of fixing any vulnerabilities. However, WordPress.org statistics show that only about half of WordPress Ninja Forms users have received the latest version, leaving around 400,000 websites vulnerable to attacks.
The first vulnerability discovered by the Patchstack team is CVE-2023-37979, a vulnerability based on a reflex POST in XSS (cross-site scripting). This vulnerability allows unauthenticated users to exploit their privileges to gain access to information by tricking privileged users into visiting a specially crafted web page.
The second and third bugs, known as CVE-2023-38393 and CVE-2023-38386 respectively, involve access control issues in the plugin's form submission export feature. This allows Subscribers and Contributors to retrieve all data submitted by users on the affected WordPress site.
See also: WooCommerce Stripe Gateway plugin – WordPress: Vulnerability exposes user order details

Although the issues are rated as high severity, CVE-2023-38393 is particularly dangerous because it is easy to encounter a user with a subscriber role. Any website that supports membership and user registrations is vulnerable to a potential mass data breach if it uses a vulnerable version of the Ninja Forms plugin.
The patches implemented by the vendor in version 3.6.26 include the addition of permission checks to address access control issues and feature access restrictions that prevent the risk of identified XSS attacks.
The public reporting of the above flaws was delayed for over three weeks, in order to prevent hackers from drawing attention to the flaws, while also giving users to fix them. However, there is still a significant number of people who have not taken this action so far.
Patchstack's coverage includes detailed technical information about the three vulnerabilities, so exploiting them shouldn't be a big deal for informed threat actors.
With that being said, it is recommended that all site administrators using the Ninja Forms plugin update to version 3.6.26 or later as soon as possible. If this is not possible, administrators should disable the plugin from their sites until they can implement the code.
See also: WordPress: Automatic update to fix vulnerability in Jetpack plugin
WordPress is one of the most popular content management systems (CMS) in the world, providing a flexible and intelligent platform for building and managing websites. Although WordPress is designed with security in mind, its open source nature means it is a target for malicious users. It is essential for every WordPress website administrator to stay up to date with the latest security threats and regularly apply updates and patches to ensure their website remains secure.
