First published: Wed Jan 06 2021(Updated: )
The Ninja Forms plugin before 3.4.28 for WordPress lacks escaping for submissions-table fields.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ninja Forms | <3.4.28 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-36173 is a vulnerability in the Ninja Forms plugin for WordPress that allows for SQL injection attacks.
If you are using the Ninja Forms plugin for WordPress with a version prior to 3.4.28, your website may be vulnerable to SQL injection attacks.
The severity of CVE-2020-36173 is rated as medium, with a severity value of 5.3.
To fix CVE-2020-36173, you should update the Ninja Forms plugin to version 3.4.28 or above, which includes the necessary escaping for submissions-table fields.
You can find more information about CVE-2020-36173 on the official Ninja Forms plugin page: https://wordpress.org/plugins/ninja-forms/#developers