cleantalk
Vulnerabilities and Security Researches

Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress, 4d853456ce172f350a9d0a401ea82c05e7ce461c

Published on
Apr 20, 2015
Research Description
Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 2.9.11 Ninja Forms <= 2.9.10 - Reflected Cross-Site Scripting The Ninja Forms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.9.10 due to insufficient input sanitization and output escaping on add_query_arg and remove_query_arg. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
Affected versions
max 2.9.11.
Status
vulnerable