Input validation vulnerability in Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress 2.9.55.2

The Ninja Forms Contact Form plugin for WordPress is vulnerable to a type of cyber attack called SQL Injection. This affects versions up to 2.9.55.1 of the plugin. The problem is that the plugin does not properly protect user information, and also does not take the necessary steps to secure the database. This makes it possible for attackers, even those with low-level access, to access sensitive information stored in the database.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.