CVE · Medium

CVE-2020-36173 — Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.4.28

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2020-36173 Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.4.28 Improper Encoding or Escaping of Output Medium 5.3 < 3.4.28 3.4.28 2020-09-20

CVE-2020-36173

The plugin failed to properly sanitize user-submitted HTML content stored in the submissions table, potentially allowing malicious scripts to be injected and executed on user's browsers, leading to cross-site scripting vulnerabilities.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.