Input validation vulnerability in Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress 2.9.18

The Ninja Forms Contact Form plugin for WordPress is vulnerable to a security issue where it is possible for an unauthorized user to inject malicious web scripts into a website. This would cause the scripts to run in the web browser of a visitor to the website, without their knowledge or permission. This vulnerability affects versions of the Ninja Forms plugin from 2.9.18 and earlier. It is caused by the plugin not doing enough to prevent malicious scripts from entering the website, and not doing enough to prevent them from running.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.