First published: Wed Jan 06 2021(Updated: )
The Ninja Forms plugin before 3.4.27.1 for WordPress allows CSRF via services integration.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ninja Forms | <3.4.27.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-36174.
The severity of CVE-2020-36174 is medium.
The Ninja Forms plugin vulnerability CVE-2020-36174 occurs due to CSRF (Cross-Site Request Forgery) via services integration.
The version of the Ninja Forms plugin affected by CVE-2020-36174 is before 3.4.27.1.
To fix the Ninja Forms plugin vulnerability CVE-2020-36174, update the plugin to version 3.4.27.1 or later.