WordPress Ninja Forms Code Injection

Discussion in 'News Aggregator' started by Packet Storm, 21 Jun 2022.

  1. Packet Storm

    Packet Storm Guest

    The Wordfence Threat Intelligence team uncovered a code injection vulnerability that made it possible for unauthenticated attackers to call a limited number of methods in various Ninja Forms classes, including a method that unserialized user-supplied content, resulting in Object Injection. This could allow attackers to execute arbitrary code or delete ar bitrary files on sites where a separate POP chain was present. This flaw has been fully patched in versions 3.0.34.2, 3.1.10, 3.2.28, 3.3.21.4, 3.4.34.2, 3.5.8.4, and 3.6.11.

    Continue reading...
     

Share This Page

Loading...