WordPress Ninja Forms Unauthenticated File Upload

Discussion in 'News Aggregator' started by Packet Storm, 27 May 2016.

  1. Packet Storm

    Packet Storm Guest

    Versions 2.9.36 to 2.9.42 of the Ninja Forms plugin contain an unauthenticated file upload vulnerability, allowing guests to upload arbitrary PHP code that can be executed in the context of the web server.

    Continue reading...
     

Share This Page

Loading...