cleantalk
Vulnerabilities and Security Researches

Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress, 8843d66b-e895-4336-afda-00b99442cdc1

Published on
-
Research Description
Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.6.11 Ninja Forms &lt; 3.6.11 - Unauthenticated PHP Object Injection The plugin does not validate merge tags provided in the request, which could allow unauthenticated attackers to call any static method present in the blog. One from the plugin in particular could allow for PHP Object Injection when a suitable gadget is also present on the blog. Attackers have been exploiting such issue since June 9th, 2022
Affected versions
max 3.6.11.
Status
vulnerable