Path Traversal and Unrestricted File Upload exists in the Ninja Forms plugin before 3.0.23 for WordPress (when the Uploads add-on is activated). This allows an attacker to traverse the file system to…
High CVSS 8.1
Summary
Path Traversal and Unrestricted File Upload exists in the Ninja Forms plugin before 3.0.23 for WordPress (when the Uploads add-on is activated). This allows an attacker to traverse the file system to access files and execute code via the includes/fields/upload.php (aka upload/submit page) name and tmp_name parameters.
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
Sources
- NVD DATABASE
Original Links
- https://wpscan.com/vulnerability/e5898e0e-db43-4641-b2cd-f6a72cdb8993/
- https://wpvulndb.com/vulnerabilities/9272 Third Party Advisory
- https://www.onvio.nl/nieuws/ninjaforms-vulnerability Exploit
- https://wpvulndb.com/vulnerabilities/9272 Third Party Advisory
- https://www.onvio.nl/nieuws/ninjaforms-vulnerability Exploit
Timeline
- nvd_ingest NVD