CVE-2023-35909 MEDIUM

CVE-2023-35909: WordPress Ninja Forms Plugin <= 3.6.25 is vulnerable to Denial of Service Attack

Vendor Saturday Drive
Product Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress
Weakness CWE-400
Published December 7, 2023
Last update April 28, 2026

CVSS base score

5.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality None
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

What the vulnerability does

01Description

Uncontrolled Resource Consumption vulnerability in Saturday Drive Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress leading to DoS.This issue affects Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress: from n/a through 3.6.25.

Key dates

02Disclosure timeline

December 7, 2023 CVE published
April 28, 2026 Record updated