CVE-2022-0889: Ninja Forms - File Uploads Extension <= 3.3.12 - Reflected Cross-Site Scripting
The Ninja Forms - File Uploads Extension WordPress plugin is vulnerable to reflected cross-site scripting due to missing sanitization of the files filename parameter found in the ~/includes/ajax/controllers/uploads.php file which can be used by unauthenticated attackers to add malicious web scripts to vulnerable WordPress sites, in versions up to and including 3.3.12.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2022-0889.
What is the title of the vulnerability?
The title of the vulnerability is 'The Ninja Forms - File Uploads Extension WordPress plugin is vulnerable to reflected cross-site scripting.'
What is the severity of CVE-2022-0889?
The severity of CVE-2022-0889 is medium with a CVSS score of 6.1.
How does the vulnerability affect the Ninja Forms - File Uploads Extension WordPress plugin?
The vulnerability affects the Ninja Forms - File Uploads Extension WordPress plugin version up to and including 3.3.12.
How can the vulnerability be exploited?
The vulnerability can be exploited by unauthenticated attackers using malicious web scripts.