{"id":29064,"date":"2016-08-24T14:39:41","date_gmt":"2016-08-24T11:39:41","guid":{"rendered":"http:\/\/blog.superhosting.bg\/en\/?p=29064"},"modified":"2022-03-28T19:59:31","modified_gmt":"2022-03-28T16:59:31","slug":"ninja-forms-vulnerability","status":"publish","type":"post","link":"https:\/\/blog.superhosting.bg\/en\/ninja-forms-vulnerability.html","title":{"rendered":"SQL Injection Vulnerability in Ninja Forms Fixed"},"content":{"rendered":"<p>Recently we detected a SQL Injection vulnerability in&nbsp;<a title=\"Ninja Forms\" href=\"https:\/\/wordpress.org\/plugins\/ninja-forms\/\" target=\"_blank\" rel=\"noopener\">Ninja Forms<\/a>, which is one of the most popular WordPress plugins. However, the issue was quickly resolved and you are still safe with us.<br \/>\nFor the past few days this has been a very hot topic among the WordPress community. In a nutshell \u2013 the vulnerability enables hackers to execute SQL queries in order to easily gain access to the website&#8217;s database. The vulnerability is due to the fact that the plugin does not properly validate input user data which enables executing the <a title=\"SQL Injection\" href=\"https:\/\/en.wikipedia.org\/wiki\/SQL_injection\" target=\"_blank\" rel=\"noopener\">SQL Injection<\/a> in the database.<\/p>\n<p>This allows any registered WordPress user to breach into the system regardless of the access level.<\/p>\n<div style=\"background: none repeat scroll 0% 0% #ddeef9; padding: 10px; margin: 1px;\">\n<p>But fixing this vulnerability is already a feature of our&nbsp;<a title=\"Security system\" href=\"https:\/\/blog.superhosting.bg\/en\/protection-by-superhosting.html\" target=\"_blank\" rel=\"noopener\">Security system<\/a>. Just in case, we recommend that you upgrade the plugin to the last version available.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>But fixing this vulnerability is already a feature of our Security system. Just in case, we recommend that you upgrade the plugin to the last version available.<\/p>\n","protected":false},"author":7,"featured_media":53911,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"_lmt_disableupdate":"","_lmt_disable":"","footnotes":""},"categories":[110],"tags":[136],"class_list":{"0":"post-29064","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-superhosting-technology-en","8":"tag-security-system"},"aioseo_notices":[],"modified_by":"\u041c\u0430\u0434\u043b\u0435\u043d\u0430 \u041c\u0435\u0442\u043e\u0434\u0438\u0435\u0432\u0430","post_mailing_queue_ids":[],"_links":{"self":[{"href":"https:\/\/blog.superhosting.bg\/en\/wp-json\/wp\/v2\/posts\/29064","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.superhosting.bg\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.superhosting.bg\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.superhosting.bg\/en\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.superhosting.bg\/en\/wp-json\/wp\/v2\/comments?post=29064"}],"version-history":[{"count":2,"href":"https:\/\/blog.superhosting.bg\/en\/wp-json\/wp\/v2\/posts\/29064\/revisions"}],"predecessor-version":[{"id":64313,"href":"https:\/\/blog.superhosting.bg\/en\/wp-json\/wp\/v2\/posts\/29064\/revisions\/64313"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blog.superhosting.bg\/en\/wp-json\/wp\/v2\/media\/53911"}],"wp:attachment":[{"href":"https:\/\/blog.superhosting.bg\/en\/wp-json\/wp\/v2\/media?parent=29064"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.superhosting.bg\/en\/wp-json\/wp\/v2\/categories?post=29064"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.superhosting.bg\/en\/wp-json\/wp\/v2\/tags?post=29064"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}