S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-24165 Scanner

CVE-2021-24165 scanner - Open Redirect vulnerability in Ninja Forms plugin for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.4k
Times Used
continuous scan runs
4.1k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-24165
6.1
CVSS

In the Ninja Forms Contact Form WordPress plugin before 3.4.34, the wp_ajax_nf_oauth_connect AJAX action was vulnerable to open redirect due to the use of a user supplied redirect parameter and no protection in place.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress
AFFECTED< 3.4.34SAFE ✓≥ 3.4.34
Updated Aug 21, 2026View on NVD →
Detail

Ninja Forms is a popular WordPress plugin that provides customizable forms for websites. It is used by businesses and bloggers alike to create contact forms, surveys, registration forms, and more. The plugin is highly user-friendly, allowing even those with little technical knowledge to create professional-looking forms with ease.

However, recently, a critical vulnerability was discovered in Ninja Forms. The CVE-2021-24165 vulnerability was spotted in the wp_ajax_nf_oauth_connect AJAX action. It left the plugin open to open redirects, which attackers could use to redirect users to malicious sites. This could lead to phishing attacks, identity theft, or other dangerous activities.

If exploited, the vulnerability posed a significant threat to website owners and users alike. Sensitive information such as usernames, passwords, and other private details could be compromised. Furthermore, redirects to malicious websites could lead to malware infections, ransomware attacks, and other malicious activities.

At S4E, we take digital security seriously. Our platform provides users with up-to-date information on known vulnerabilities, security threats, and other digital security issues. By using our pro features, businesses can keep their assets safe and secure, protecting themselves and their customers from potential harm. Don't leave your digital security to chance - sign up for S4E today.

 

REFERENCES

Solution Advice

To protect against this vulnerability, website owners should ensure they have taken the following precautions:

  • Update to the latest version of Ninja Forms (3.4.34), which includes a security fix.
  • Limit user access to the wp_ajax_nf_oauth_connect AJAX action.
  • Use a firewall, antivirus program, and other cybersecurity tools to protect against malware infections.
  • Educate employees and website visitors on the dangers of phishing attacks.
  • Regularly monitor website traffic and activity for signs of malicious activity.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.