CVE-2020-36174: CSRF
Published Jan 6, 2021
·Updated
The Ninja Forms plugin before 3.4.27.1 for WordPress allows CSRF via services integration.
Affected Software
1 affected component
NinjaForms Ninja Forms Wordpress<3.4.27.1
Event History
Jan 6, 2021
CVE Published
via MITRE·02:31 PM
Data Sourced
via MITRE·02:31 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2020-36174.
2
What is the severity of CVE-2020-36174?
The severity of CVE-2020-36174 is medium.
3
How does the Ninja Forms plugin vulnerability CVE-2020-36174 occur?
The Ninja Forms plugin vulnerability CVE-2020-36174 occurs due to CSRF (Cross-Site Request Forgery) via services integration.
4
Which version of the Ninja Forms plugin is affected by CVE-2020-36174?
The version of the Ninja Forms plugin affected by CVE-2020-36174 is before 3.4.27.1.
5
How can I fix the Ninja Forms plugin vulnerability CVE-2020-36174?
To fix the Ninja Forms plugin vulnerability CVE-2020-36174, update the plugin to version 3.4.27.1 or later.