CVE-2020-36175: Input Validation
Published Jan 6, 2021
·Updated
The Ninja Forms plugin before 3.4.27.1 for WordPress allows attackers to bypass validation via the email field.
Affected Software
1 affected component
NinjaForms Ninja Forms Wordpress<3.4.27.1
Event History
Jan 6, 2021
CVE Published
via MITRE·02:31 PM
Data Sourced
via MITRE·02:31 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for the Ninja Forms plugin?
The vulnerability ID for the Ninja Forms plugin is CVE-2020-36175.
2
What is the severity of CVE-2020-36175?
The severity of CVE-2020-36175 is medium.
3
How does the vulnerability in the Ninja Forms plugin allow attackers to bypass validation?
The vulnerability allows attackers to bypass validation via the email field.
4
What version of the Ninja Forms plugin is affected by CVE-2020-36175?
The Ninja Forms plugin version up to and excluding 3.4.27.1 is affected by CVE-2020-36175.
5
How can I fix CVE-2020-36175 in the Ninja Forms plugin?
To fix CVE-2020-36175, update the Ninja Forms plugin to version 3.4.27.1 or later.