Lucene search

K
cvelistWPScanCVELIST:CVE-2021-24889
HistoryNov 29, 2021 - 8:25 a.m.

CVE-2021-24889 Ninja Forms < 3.6.4 - Admin+ SQL Injection

2021-11-2908:25:45
CWE-89
WPScan
www.cve.org
3
cve-2021-24889
ninja forms
wordpress
sql injection
security vulnerability

EPSS

0.001

Percentile

37.7%

The Ninja Forms Contact Form WordPress plugin before 3.6.4 does not escape keys of the fields POST parameter, which could allow high privilege users to perform SQL injections attacks

CNA Affected

[
  {
    "product": "Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress",
    "vendor": "Unknown",
    "versions": [
      {
        "lessThan": "3.6.4",
        "status": "affected",
        "version": "3.6.4",
        "versionType": "custom"
      }
    ]
  }
]

EPSS

0.001

Percentile

37.7%