First published: Mon Nov 29 2021(Updated: )
The Ninja Forms Contact Form WordPress plugin before 3.6.4 does not escape keys of the fields POST parameter, which could allow high privilege users to perform SQL injections attacks
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ninja Forms | <3.6.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2021-24889.
The severity of CVE-2021-24889 is high with a CVSS score of 7.2.
The affected software is the Ninja Forms Contact Form WordPress plugin version up to 3.6.4.
This vulnerability allows high privilege users to perform SQL injection attacks.
To fix CVE-2021-24889, update the Ninja Forms Contact Form WordPress plugin to version 3.6.4 or later.