CVE-2020-36173: Medium severity ninja forms vulnerability
Published Jan 6, 2021
·Updated
The Ninja Forms plugin before 3.4.28 for WordPress lacks escaping for submissions-table fields.
Affected Software
1 affected component
NinjaForms Ninja Forms Wordpress<3.4.28
Event History
Jan 6, 2021
CVE Published
via MITRE·02:32 PM
Data Sourced
via MITRE·02:32 PM
Description
Frequently Asked Questions
1
What is CVE-2020-36173?
CVE-2020-36173 is a vulnerability in the Ninja Forms plugin for WordPress that allows for SQL injection attacks.
2
How does CVE-2020-36173 affect me?
If you are using the Ninja Forms plugin for WordPress with a version prior to 3.4.28, your website may be vulnerable to SQL injection attacks.
3
What is the severity of CVE-2020-36173?
The severity of CVE-2020-36173 is rated as medium, with a severity value of 5.3.
4
How can I fix CVE-2020-36173?
To fix CVE-2020-36173, you should update the Ninja Forms plugin to version 3.4.28 or above, which includes the necessary escaping for submissions-table fields.
5
Where can I find more information about CVE-2020-36173?
You can find more information about CVE-2020-36173 on the official Ninja Forms plugin page: https://wordpress.org/plugins/ninja-forms/#developers