30 Nov 2018

Vulnerability Details: Authenticated Open Redirect in Ninja Forms

We started the week out mentioning the issue of authenticated open redirects in popular plugins and it looks like we haven’t been the only ones look into this recently, as versionĀ 3.3.19.1 of the very popular Ninja Forms, which has 1+ million active installations according to wordpress.org, had this as its changelog entry:

...


This post provides insights on a vulnerability in the WordPress plugin Ninja Forms not discovered by us, where the discoverer hadn't provided the details needed for us to confirm the vulnerability while we were adding it to the data set for our service, so the rest of its contents are limited to subscribers of our service.

If you were using our service, you would have already been warned about this vulnerability if your website is vulnerable due to it. You can try out our service for free and then see the rest of the details of the vulnerability.

For existing customers, please log in to your account to view the rest of the contents of the post.


Plugin Security Scorecard Grade for Ninja Forms

Checked on May 15, 2025
F

See issues causing the plugin to get less than A+ grade

Leave a Reply

Your email address will not be published.