First published: Fri Feb 14 2020(Updated: )
The Ninja Forms plugin 3.4.22 for WordPress has Multiple Stored XSS vulnerabilities via ninja_forms[recaptcha_site_key], ninja_forms[recaptcha_secret_key], ninja_forms[recaptcha_lang], or ninja_forms[date_format].
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ninja Forms | =3.4.22 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-8594 refers to Multiple Stored XSS vulnerabilities in the Ninja Forms plugin 3.4.22 for WordPress.
The severity of CVE-2020-8594 is medium with a CVSS score of 5.4.
The Ninja Forms plugin 3.4.22 for WordPress is affected by CVE-2020-8594, which introduces Multiple Stored XSS vulnerabilities.
To fix the CVE-2020-8594 vulnerability, update the Ninja Forms plugin to the latest version available.
You can find more information about CVE-2020-8594 in the references provided: [https://spider-security.co.uk/blog-cve-cve-2020-8594](https://spider-security.co.uk/blog-cve-cve-2020-8594), [https://wordpress.org/plugins/ninja-forms/#developers](https://wordpress.org/plugins/ninja-forms/#developers), [https://wpvulndb.com/vulnerabilities/10070](https://wpvulndb.com/vulnerabilities/10070).