CVE-2021-25066 Information
Jul 06, 2022
cve
Description
The Ninja Forms Contact Form WordPress plugin before 3.6.10 does not sanitize and escape some imported data allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
Reference
https://wpscan.com/vulnerability/323d5fd0-abe8-44ef-9127-eea6fd4f3f3d
Share on: