Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress, 8843d66b-e895-4336-afda-00b99442cdc1
- CVE, Research URL
- Home page URL
-
Security reports for Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress
- Published on
- -
- Research Description
- Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.6.11 Ninja Forms < 3.6.11 - Unauthenticated PHP Object Injection The plugin does not validate merge tags provided in the request, which could allow unauthenticated attackers to call any static method present in the blog. One from the plugin in particular could allow for PHP Object Injection when a suitable gadget is also present on the blog. Attackers have been exploiting such issue since June 9th, 2022
- Affected versions
-
max 3.6.11.
- Status
-
vulnerable