CVE-2016-1209: Input Validation
Published May 14, 2016
·Updated
The Ninja Forms plugin before 2.9.42.1 for WordPress allows remote attackers to conduct PHP object injection attacks via crafted serialized values in a POST request.
Affected Software
1 affected component
NinjaForms Ninja Forms Wordpress<=2.9.42
Event History
May 14, 2016
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-1209?
CVE-2016-1209 has been classified as a medium severity vulnerability due to its potential for PHP object injection attacks.
2
How do I fix CVE-2016-1209?
To fix CVE-2016-1209, update the Ninja Forms plugin to version 2.9.42.1 or later.
3
Who is affected by CVE-2016-1209?
CVE-2016-1209 affects users of the Ninja Forms plugin prior to version 2.9.42.1 on WordPress.
4
What type of attack can CVE-2016-1209 facilitate?
CVE-2016-1209 can facilitate PHP object injection attacks via crafted serialized values.
5
What versions of Ninja Forms are vulnerable to CVE-2016-1209?
Versions of Ninja Forms prior to 2.9.42.1 are vulnerable to CVE-2016-1209.