CVE

CVE-2015-2220 — Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 2.8.9

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2015-2220 Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 2.8.9 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Unknown < 2.8.9 2.8.9 2014-11-20

CVE-2015-2220

The Ninja Forms plugin for WordPress contains two vulnerabilities that allow an attacker to inject malicious code into a website. In the first case, an attacker can inject arbitrary web script or HTML by manipulating the "ninja_forms_field_1" parameter in a specific action, potentially allowing them to take control of a user's session. In the second case, a remote administrator can inject malicious code by manipulating the "fields[1]" parameter, which could compromise the security of the entire website.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.