CVE-2020-12462: XSS
The ninja-forms plugin before 3.4.24.2 for WordPress allows CSRF with resultant XSS.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-12462?
CVE-2020-12462 is a vulnerability in the ninja-forms plugin for WordPress that allows CSRF (Cross-Site Request Forgery) with resultant XSS (Cross-Site Scripting).
How severe is CVE-2020-12462?
CVE-2020-12462 has a severity rating of medium, with a CVSS score of 6.1.
What is the affected software in CVE-2020-12462?
The affected software in CVE-2020-12462 is the ninja-forms plugin for WordPress version up to exclusive 3.4.24.2.
What is CSRF?
CSRF stands for Cross-Site Request Forgery, which is an attack that tricks the victim into performing unwanted actions on a web application in which they are authenticated.
What is XSS?
XSS stands for Cross-Site Scripting, which is a type of vulnerability that allows attackers to inject malicious scripts into web pages viewed by other users.