Exploitation Summary
EIP tracks 2 public exploits for CVE-2016-1209.
PoCs published by Metasploit, James Golovich, rastating, including Metasploit module exploits/multi/http/wp_ninja_forms_unauthenticated_file_upload.
AI-analyzed exploit summary This Metasploit module exploits an unauthenticated file upload vulnerability in WordPress Ninja Forms (CVE-2016-1209), allowing arbitrary PHP code execution by uploading a malicious file via a vulnerable V3 preview mode.
Description
The Ninja Forms plugin before 2.9.42.1 for WordPress allows remote attackers to conduct PHP object injection attacks via crafted serialized values in a POST request.
Exploits (2)
This Metasploit module exploits an unauthenticated file upload vulnerability in WordPress Ninja Forms (CVE-2016-1209), allowing arbitrary PHP code execution by uploading a malicious file via a vulnerable V3 preview mode.
This Metasploit module exploits an unauthenticated file upload vulnerability in WordPress Ninja Forms (versions 2.9.36 to 2.9.42) by enabling V3 functionality, fetching a nonce, uploading a malicious PHP payload, and executing it.
References (8)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H