CVE-2021-25066
04.07.2022, 13:15
The Ninja Forms Contact Form WordPress plugin before 3.6.10 does not sanitize and escape some imported data, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
Vendor | Product | Version |
---|---|---|
ninjaforms | ninja_forms | 𝑥 < 3.6.10 |
𝑥
= Vulnerable software versions