The Ninja Forms Contact Form WordPress plugin before 3.6.4 does not escape keys of the fields POST parameter, which could allow high privilege users to perform SQL injections attacks
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2021-11-29T08:25:45

Updated: 2024-08-03T19:49:13.490Z

Reserved: 2021-01-14T00:00:00

Link: CVE-2021-24889

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2021-11-29T09:15:07.800

Modified: 2021-11-29T20:28:48.287

Link: CVE-2021-24889

cve-icon Redhat

No data.