CVE-2018-7280: XSS
Published Feb 21, 2018
·Updated
The Ninja Forms plugin before 3.2.14 for WordPress has XSS.
Affected Software
1 affected component
NinjaForms Ninja Forms Wordpress<3.2.14
Event History
Feb 21, 2018
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Data Sourced
via NVD·04:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for the Ninja Forms plugin?
The vulnerability ID for the Ninja Forms plugin is CVE-2018-7280.
2
What is the severity of CVE-2018-7280?
The severity of CVE-2018-7280 is medium with a severity score of 6.1.
3
What is affected by CVE-2018-7280?
The Ninja Forms plugin before version 3.2.14 for WordPress is affected by CVE-2018-7280.
4
What is the impact of CVE-2018-7280?
CVE-2018-7280 allows for cross-site scripting (XSS) attacks in the Ninja Forms plugin.
5
How can I fix CVE-2018-7280?
To fix CVE-2018-7280, update the Ninja Forms plugin to version 3.2.14 or above.