CVE-2023-4109 – Ninja Forms < 3.6.26 - Admin+ Stored HTML Injection
https://notcve.org/view.php?id=CVE-2023-4109
The Ninja Forms WordPress Ninja Forms Contact Form WordPress plugin before 3.6.26 was affected by a HTML Injection security vulnerability. El plugin Ninja Forms para WordPress anterior a la versión 3.6.26 estaba afectado por una vulnerabilidad de seguridad de inyección HTML. The Ninja Forms plugin for WordPress is vulnerable to Stored HTML Injection in versions up to, and including, 3.6.25 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrator access to inject arbitrary HTML content in pages that will execute whenever a user accesses an injected page. • https://wpscan.com/vulnerability/558e06ab-704b-4bb1-ba7f-b5f6bbbd68d9 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •