cleantalk
Vulnerabilities and Security Researches

Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress, 0bc642976d29821d5fd23074ac0888a4976b0eab

Published on
Apr 17, 2017
Research Description
Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.0.32 Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress <= 3.0.31 - Arbitrary Wordpress Shortcode Injection The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Arbitrary Wordpress Shortcode Injection in versions up to, and including, 3.0.31. This makes it possible for unauthenticated attackers to preview un-published forms and could possibly be used to leverage further attacks.
Affected versions
max 3.0.32.
Status
vulnerable