Ninja Forms (WordPress) Update
2676Warning Date
Severity Level
Warning Number
Target Sector
3 May, 2020
● High
2020-1195
All
Description:
Wordfence has released security update to address a vulnerability in the following plugin:
- Ninja Forms
- Versions before 3.4.24.2
Threats:
Attacker could exploit this vulnerability by doing the following:
- Stored cross-site scripting (XSS) attack.
- Cross-site request forgery (CSRF).
Best practice and Recommendations:
The CERT team encourages users to review Wordfence security advisory and apply the necessary updates: