cleantalk
Vulnerabilities and Security Researches

Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress, CVE-2021-24889

CVE, Research URL

CVE-2021-24889

Published on
Nov 29, 2021
Research Description
The Ninja Forms Contact Form WordPress plugin before 3.6.4 does not escape keys of the fields POST parameter, which could allow high privilege users to perform SQL injections attacks
Affected versions
Min -, max 3.6.4.
Status
vulnerable