cleantalk
Vulnerabilities and Security Researches

Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress, f815fadab1550c44ce7eabd76f9d3a6bfb0e7524

Published on
Sep 22, 2020
Research Description
Ninja Forms &#8211; The Contact Form Builder That Grows With You [ninja-forms] < 3.4.27.1 WordPress Ninja Forms plugin <= 3.4.27 - Cross-Site Request Forgery (CSRF) leading to Arbitrary Plugin Installation vulnerability Cross-Site Request Forgery (CSRF) leading to Arbitrary Plugin Installation vulnerability found by Slavco Mihajloski in WordPress Ninja Forms plugin (versions <= 3.4.27).
Affected versions
max 3.4.27.1.
Status
vulnerable