Nasty WordPress plugin vulnerabilities puts over a million sites at risk

Unbreakable Lock
(Image credit: KAUST)

Two vulnerabilities in the popular Ninja Forms WordPress plugin could’ve enabled threat actors to export sensitive information and send phishing emails from a vulnerable site, report security researchers.

In their breakdown of the vulnerability, cybersecurity researchers from Wordfence, which develops security solutions to protect WordPress installations, note that Ninja Forms boasts of an installation base of over one million websites.

The researchers explain that the vulnerabilities existed because the popular form building plugin relied on an insecure implementation of the mechanism that checks a user’s permissions.

The insecure implementation meant that instead of ensuring a logged-in user had the right permissions to trigger the associated action, the function only checked if the user was in fact logged-in or not, and nothing else.

Who is it?

One of the issues, a bulk submission export vulnerability, could enable any logged-in user, irrespective of their permissions level, to export everything that had ever been submitted to one of the site’s forms. 

The other issue enabled any user to send an email from a vulnerable WordPress website to any email address. 

“This vulnerability could easily be used to create a phishing campaign that could trick unsuspecting users into performing unwanted actions by abusing the trust in the domain that was used to send the email,” suggests Wordfence, adding that it could also be used to trick the website’s admins as well to facilitate a site takeover campaign.

Wordfence responsibly disclosed the vulnerability to Ninja Forms on August 3, 2021, who acknowledged it immediately and released a patch earlier this month in the form of Ninja Forms v3.5.8.

TOPICS
Mayank Sharma

With almost two decades of writing and reporting on Linux, Mayank Sharma would like everyone to think he’s TechRadar Pro’s expert on the topic. Of course, he’s just as interested in other computing topics, particularly cybersecurity, cloud, containers, and coding.

Read more
WordPress
Another top WordPress plugin found carrying critical security flaws
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
Over a million WordPress sites exposed to attack from W3 Total Cache plugin flaw
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
Another serious WordPress plugin vulnerability could put 40,000 sites at risk of attack
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
Thousands of WordPress websites hit in new malware attack, here's what we know
WordPress
WordPress users beware - these popular theme plugins have some major security issues
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
This top WordPress plugin could be hiding a worrying security flaw, so be on your guard
Latest in Security
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand
Lock on Laptop Screen
Medusa ransomware is able to disable anti-malware tools, so be on your guard
An abstract image of digital security.
Fake file converters are stealing info, pushing ransomware, FBI warns
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Coinbase targeted after recent Github attacks
hacker.jpeg
Key trusted Microsoft platform exploited to enable malware, experts warn
IBM office logo
IBM to provide platform for flagship cyber skills programme for girls
Latest in News
Zendesk Relate 2025
Zendesk Relate 2025 - everything you need to know as the event unfolds
Disney Plus logo with popcorn
You can finally tell Disney+ to stop bugging you about that terrible Marvel show you regret starting
Google Gemini AI
Gemini can now see your screen and judge your tabs
Girl wearing Meta Quest 3 headset interacting with a jungle playset
Latest Meta Quest 3 software beta teases a major design overhaul and VR screen sharing – and I need these updates now
Philips Hue
Philips Hue might be working on a video doorbell, and according to a new report, we just got our first look at it
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand