First published: Mon Sep 26 2022(Updated: )
The Ninja Forms Contact Form WordPress plugin before 3.6.13 unserialises the content of an imported file, which could lead to PHP object injections issues when an admin import (intentionally or not) a malicious file and a suitable gadget chain is present on the blog.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ninja Forms | <3.6.13 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this plugin is CVE-2022-2903.
The severity of CVE-2022-2903 is high with a CVSS score of 7.2.
The affected software is the Ninja Forms Contact Form WordPress plugin before version 3.6.13.
CVE-2022-2903 is a vulnerability in the Ninja Forms Contact Form WordPress plugin that allows PHP object injection issues when malicious files are imported and suitable gadget chains are present on the blog.
To fix CVE-2022-2903, update the Ninja Forms Contact Form plugin to version 3.6.13 or later.