First published: Wed Apr 29 2020(Updated: )
The ninja-forms plugin before 3.4.24.2 for WordPress allows CSRF with resultant XSS.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ninja Forms | <3.4.24.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-12462 is a vulnerability in the ninja-forms plugin for WordPress that allows CSRF (Cross-Site Request Forgery) with resultant XSS (Cross-Site Scripting).
CVE-2020-12462 has a severity rating of medium, with a CVSS score of 6.1.
The affected software in CVE-2020-12462 is the ninja-forms plugin for WordPress version up to exclusive 3.4.24.2.
CSRF stands for Cross-Site Request Forgery, which is an attack that tricks the victim into performing unwanted actions on a web application in which they are authenticated.
XSS stands for Cross-Site Scripting, which is a type of vulnerability that allows attackers to inject malicious scripts into web pages viewed by other users.