CVE-2021-24889: Ninja Forms < 3.6.4 - Admin+ SQL Injection
Published Nov 29, 2021
·Updated
The Ninja Forms Contact Form WordPress plugin before 3.6.4 does not escape keys of the fields POST parameter, which could allow high privilege users to perform SQL injections attacks
Affected Software
1 affected component
NinjaForms Ninja Forms Wordpress<3.6.4
Event History
Nov 29, 2021
CVE Published
via MITRE·08:25 AM
Data Sourced
via MITRE·08:25 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2021-24889.
2
What is the severity of CVE-2021-24889?
The severity of CVE-2021-24889 is high with a CVSS score of 7.2.
3
What is the affected software?
The affected software is the Ninja Forms Contact Form WordPress plugin version up to 3.6.4.
4
What is the impact of this vulnerability?
This vulnerability allows high privilege users to perform SQL injection attacks.
5
How can I fix CVE-2021-24889?
To fix CVE-2021-24889, update the Ninja Forms Contact Form WordPress plugin to version 3.6.4 or later.