First published: Sat May 14 2016(Updated: )
The Ninja Forms plugin before 2.9.42.1 for WordPress allows remote attackers to conduct PHP object injection attacks via crafted serialized values in a POST request.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Ninja Forms | <=2.9.42 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-1209 has been classified as a medium severity vulnerability due to its potential for PHP object injection attacks.
To fix CVE-2016-1209, update the Ninja Forms plugin to version 2.9.42.1 or later.
CVE-2016-1209 affects users of the Ninja Forms plugin prior to version 2.9.42.1 on WordPress.
CVE-2016-1209 can facilitate PHP object injection attacks via crafted serialized values.
Versions of Ninja Forms prior to 2.9.42.1 are vulnerable to CVE-2016-1209.