Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress, 0bc642976d29821d5fd23074ac0888a4976b0eab
- CVE, Research URL
- Home page URL
-
Security reports for Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress
- Published on
- Apr 17, 2017
- Research Description
- Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.0.32 Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress <= 3.0.31 - Arbitrary Wordpress Shortcode Injection The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Arbitrary Wordpress Shortcode Injection in versions up to, and including, 3.0.31. This makes it possible for unauthenticated attackers to preview un-published forms and could possibly be used to leverage further attacks.
- Affected versions
-
max 3.0.32.
- Status
-
vulnerable