CVE-2019-15025: SQL Injection
Published Aug 14, 2019
·Updated
The ninja-forms plugin before 3.3.21.2 for WordPress has SQL injection in the search filter on the submissions page.
Affected Software
1 affected component
NinjaForms Ninjaforms Wordpress<3.3.21.2
Event History
Aug 14, 2019
CVE Published
via MITRE·02:49 PM
Data Sourced
via MITRE·02:49 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2019-15025.
2
What is the severity of CVE-2019-15025?
The severity of CVE-2019-15025 is critical with a severity value of 9.8.
3
What is affected by CVE-2019-15025?
The Ninja Forms plugin before version 3.3.21.2 for WordPress is affected by CVE-2019-15025.
4
What is the impact of CVE-2019-15025?
CVE-2019-15025 allows SQL injection in the search filter on the submissions page of the Ninja Forms plugin.
5
How can I fix CVE-2019-15025?
To fix CVE-2019-15025, update to version 3.3.21.2 or later of the Ninja Forms plugin for WordPress.