CVE · Medium

CVE-2018-7280 — Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.2.14

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2018-7280 Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.2.14 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 3.2.14 3.2.14 2018-02-20

CVE-2018-7280

A security flaw was discovered in the Ninja Forms plugin for WordPress, allowing an attacker to inject malicious code into a website, potentially allowing them to steal sensitive information or take control of the site. This vulnerability, known as a Cross-Site Scripting (XSS) attack, occurred when user input was not properly sanitized, allowing malicious scripts to be executed on the site.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.