Input validation vulnerability in Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress 2.9.27

The Ninja Forms Contact Form plugin for WordPress is vulnerable to a type of security exploit called CSV Injection up to version 2.9.27. This means that an attacker who is logged in and authorized to use the plugin can embed malicious code into exported CSV files. If someone downloads and opens these files on their computer, the malicious code may be executed, allowing the attacker to gain access to the user’s system.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.