CVE-2022-2903

HIGH

Ninjaforms Ninja Forms < 3.6.13 - Insecure Deserialization

Title source: rule

Description

The Ninja Forms Contact Form WordPress plugin before 3.6.13 unserialises the content of an imported file, which could lead to PHP object injections issues when an admin import (intentionally or not) a malicious file and a suitable gadget chain is present on the blog.

Scores

CVSS v3 7.2
EPSS 0.0078
EPSS Percentile 73.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-502
Status published

Affected Products (1)

ninjaforms/ninja_forms < 3.6.13

Timeline

Published Sep 26, 2022
Tracked Since Feb 18, 2026