Ninja Forms SQL injection update immediately

There is a new vulnerability in the Ninja Forms WordPress plugin that affects all versions up to 3.6.3. Vulnerability allows , which they give to the attacker to run queries on data through the blank fields of the form.

The developer of the plugin has released the 3.6.4 two days ago.

sQL injection

The Ninja Forms add-on allows you to design forms on WordPress sites and currently has more than 1 million active installations. However, this plugin often reveals vulnerabilities, such as that reported September 22, 2021 by WordFence. The new vulnerability is supposed to have been fixed with version 3.6.4, without further details being revealed.

There is currently no detailed description of how this vulnerability identified by CVE-2021-24889 could be exploited. But on November 4, developers plan to publish a PoC that shows this.

For the record the vulnerability in the Ninja Forms plugin reported in late September involved unprotected requests through the REST API, which allowed attackers to skim off sensitive data or send emails .

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.
Ninja Forms, SQL injection, WordPress, iguru

Written by giorgos

George still wonders what he's doing here ...

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).