Description
WordPress Plugin Ninja Forms Contact Form-The Drag and Drop Form Builder for WordPress is prone to a vulnerability that lets attackers inject and execute arbitrary code because the application fails to sanitize user-supplied input. Attackers can exploit this issue to execute arbitrary PHP code within the context of the affected webserver process. WordPress Plugin Ninja Forms Contact Form-The Drag and Drop Form Builder for WordPress versions 3.0-3.0.34.1, 3.1-3.1.9, 3.2-3.2.27, 3.3-3.3.21.3, 3.4-3.4.34.1, 3.5-3.5.8.3, 3.6-3.6.10 are vulnerable.
Remediation
Update to plugin versions 3.0.34.2, 3.1.10, 3.2.28, 3.3.21.4, 3.4.34.2, 3.5.8.4, 3.6.11 or latest
References
Related Vulnerabilities
MyBB Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2012-2327)
WebLogic CVE-2023-21839 Vulnerability (CVE-2023-21839)
MySQL CVE-2013-5894 Vulnerability (CVE-2013-5894)
WordPress Plugin Easy Forms for MailChimp Unspecified Vulnerability (6.3.2)
WordPress Plugin Easy Property Listings Unspecified Vulnerability (2.0)