Security Advisory

CVE-2022-0889

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2022-03-23 19:46:49
Last updated 2026-04-08 17:05:57
Assigner Wordfence
CVSS score 7.2
State PUBLISHED

Description

The Ninja Forms - File Uploads Extension WordPress plugin is vulnerable to reflected cross-site scripting due to missing sanitization of the files filename parameter found in the ~/includes/ajax/controllers/uploads.php file which can be used by unauthenticated attackers to add malicious web scripts to vulnerable WordPress sites, in versions up to and including 3.3.12.