Input validation vulnerability in Ninja Forms – The Contact Form Builder That Grows With You 3.8.24

A popular plugin for WordPress called Ninja Forms has a security issue that can put your website at risk. This issue, called Stored Cross-Site Scripting, allows hackers to inject harmful code into your website through a feature called shortcode. This can happen in all versions of the plugin up to version 3.8.24. The problem is caused by the plugin not properly filtering and protecting user input, allowing attackers with a certain level of access to add their own code to your website. Make sure to update to the latest version of the plugin to avoid this vulnerability.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.