First published: Wed Aug 14 2019(Updated: )
The ninja-forms plugin before 3.3.21.2 for WordPress has SQL injection in the search filter on the submissions page.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ninja Forms | <3.3.21.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2019-15025.
The severity of CVE-2019-15025 is critical with a severity value of 9.8.
The Ninja Forms plugin before version 3.3.21.2 for WordPress is affected by CVE-2019-15025.
CVE-2019-15025 allows SQL injection in the search filter on the submissions page of the Ninja Forms plugin.
To fix CVE-2019-15025, update to version 3.3.21.2 or later of the Ninja Forms plugin for WordPress.