cleantalk
Vulnerabilities and Security Researches

Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress, CVE-2016-1209

CVE, Research URL

CVE-2016-1209

Published on
May 14, 2016
Research Description
The Ninja Forms plugin before 2.9.42.1 for WordPress allows remote attackers to conduct PHP object injection attacks via crafted serialized values in a POST request.
Affected versions
Min 2.9.36, max 2.9.42.
Status
vulnerable