Description
WordPress Plugin Ninja Forms Contact Form-The Drag and Drop Form Builder for WordPress is prone to a vulnerability that lets attackers inject and execute arbitrary code because the application fails to sanitize user-supplied input. Attackers can exploit this issue to execute arbitrary PHP code within the context of the affected webserver process. WordPress Plugin Ninja Forms Contact Form-The Drag and Drop Form Builder for WordPress versions 3.0-3.0.34.1, 3.1-3.1.9, 3.2-3.2.27, 3.3-3.3.21.3, 3.4-3.4.34.1, 3.5-3.5.8.3, 3.6-3.6.10 are vulnerable.
Remediation
Update to plugin versions 3.0.34.2, 3.1.10, 3.2.28, 3.3.21.4, 3.4.34.2, 3.5.8.4, 3.6.11 or latest
References
Related Vulnerabilities
XWiki Permissions, Privileges, and Access Controls Vulnerability (CVE-2006-7223)
Oracle JRE CVE-2013-2440 Vulnerability (CVE-2013-2440)
WordPress Plugin 2Way VideoCalls and Random Chat-HTML5 Webcam Videochat Cross-Site Scripting (5.2.7)
Internet Information Services Other Vulnerability (CVE-2000-0457)