Input validation vulnerability in Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress 3.6.9

The Ninja Forms Contact Form plugin for WordPress is not secure in versions up to 3.6.9. It is possible for malicious users with administrator access to inject harmful code into webpages. This code can then be executed by anyone who visits the webpage. This vulnerability only affects WordPress installations that are part of a network or have the security setting “”unfiltered_html”” disabled.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.