vulnerability
WordPress Plugin: ninja-forms: CVE-2016-1209: Unrestricted Upload of File with Dangerous Type
Severity | CVSS | Published | Added | Modified |
---|---|---|---|---|
7 | (AV:N/AC:L/Au:N/C:P/I:P/A:P) | May 5, 2016 | May 15, 2025 | May 19, 2025 |
Severity
7
CVSS
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
Published
May 5, 2016
Added
May 15, 2025
Modified
May 19, 2025
Description
Versions 2.9.36 to 2.9.42 of the Ninja Forms plugin contain an unauthenticated file upload vulnerability, allowing guests to upload arbitrary PHP code that can be executed in the context of the web server.
Solution
ninja-forms-plugin-cve-2016-1209

NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.