mirror of
https://github.com/0xMarcio/cve.git
synced 2025-06-19 17:30:12 +00:00
1022 B
1022 B
CVE-2016-1209
Description
The Ninja Forms plugin before 2.9.42.1 for WordPress allows remote attackers to conduct PHP object injection attacks via crafted serialized values in a POST request.
POC
Reference
- http://packetstormsecurity.com/files/137211/WordPress-Ninja-Forms-Unauthenticated-File-Upload.html
- http://www.pritect.net/blog/ninja-forms-2-9-42-critical-security-vulnerabilities
- https://wpvulndb.com/vulnerabilities/8485