Input validation vulnerability in Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress 3.0.31

The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress is a plugin for WordPress websites. Unfortunately, versions up to 3.0.31 of this plugin have a security flaw which is known as Arbitrary WordPress Shortcode Injection. This vulnerability allows people who are not authorized to access the website to view forms which have not been published yet. It is also possible that this vulnerability could be used to carry out further attacks.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.