Skip to content
WPDeeply
Risk Monitor
Plugin Checker
Research
Security Guides
Plugin Security
How to judge, replace and remove WordPress plugins.
Security Research
Historical and current WordPress vulnerability disclosures.
Vulnerability Types
Plain-language explainers for the vulnerability classes that hit
Security News
New vulnerabilities, plugin removals and security releases.
Hardening
Configuration and access changes that reduce WordPress attack
Malware
Detecting, cleaning and preventing WordPress infections.
WordPress Insights
Working notes on running WordPress well, where it
Scan your plugins, themes and WordPress core for known vulnerabilities and abandoned software.
All guides
Search WPDeeply
Download free plugin
Home
/
Tag: Ninja Forms
Ninja Forms
1
Guides
All
54
Plugin Security
15
Security Research
12
Vulnerability Types
11
Security News
6
Hardening
5
Malware
5
WordPress Insights
4
RSS
Ninja Forms before 3.4.27.1 — Simple CSRF to RCE
A missing request-origin check in Ninja Forms let one crafted link, clicked by a logged-in administrator, escalate into code execution. Fixed in 3.4.27.1.
Security Research
8 Oct 2020, 4 min