CVE-2021-34647


Ninja Forms <= 3.5.7 Sensitive Information Disclosure

The Ninja Forms WordPress plugin is vulnerable to sensitive information disclosure via the bulk_export_submissions function found in the ~/includes/Routes/Submissions.php file, in versions up to and including 3.5.7. This allows authenticated attackers to export all Ninja Forms submissions data via the /ninja-forms-submissions/export REST API which can include personally identifiable information.



We have discovered 44 live websites that are affected by CVE-2021-34647.

Contact us to get more info




Affected Software

Product  Ninja Forms
Category Wordpress Plugins
Vulnerable Versions
  • from 3.5.7 through 3.5.7
Total Vulnerable Versions207
Vulnerable Domains44 live websites (0.19% of Ninja Forms install base)


Common Weakness Enumeration


CWE-863 Incorrect Authorization


Distribution by Website Rank

The diagram provides a graphic representation of the correlation between the occurrence of CVE-2021-34647 and the relative popularity of websites


Details

  • Published - Sep 22, 2021
  • Updated - Sep 23, 2021

Credits

  • Chloe Chamberland, Wordfence





Countries

United States13 websites



Canada6 websites
Australia4 websites
Germany4 websites
GB3 websites
France2 websites
India2 websites
Italy2 websites
Belgium1 websites
Bulgaria1 websites

TLDs

.com19 websites
.org5 websites
.ca4 websites
.com.au4 websites
.de2 websites
.be1 websites
.co1 websites
.co.uk1 websites
.jp1 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


Geographical Distribution

The distribution of websites across the globe that are exposed to CVE-2021-34647 through included software libraries and plugins.



References


Websites affected by CVE-2021-34647

Top websites that are affected by CVE-2021-34647. Please click on the "Contact us" button above to get more information.
DomainCountryRankContacts
***********.com Canada**,***
****.**********.com Italy***,***
***.********.ec Ecuador*,***,***
***.***********.com United States*,***,***
******************.com United States*,***,***
***.*************.com France*,***,***
***.*****.***.au Australia*,***,***
********.be Belgium*,***,***
*****************.com United States*,***,***
************.de Germany*,***,***
See full domain list