plugin

Ninjafirewall Vulnerabilities

5 known security issues reported for the Ninjafirewall WordPress plugin. Most recent disclosed Oct 16, 2024.

1 medium

Running Ninjafirewall on your site? Check whether your installed version is affected.

Scan your site free

NinjaFirewall (WP Edition) &#8211; Advanced Security Plugin and Firewall [ninjafirewall] < 4.3.4

unknown

[en] The NinjaFirewall plugin for WordPress is vulnerable to Authenticated PHAR Deserialization in versions up to, and including, 4.3.3. This allows authenticated attackers to perform phar deserialization on the server. This deserialization can allow other plugin or theme exploits if vulnerable software is present (Wo...

Affected:
up to 4.3.4
Fixed in:
4.3.4
Disclosed:
Oct 16, 2024

CVE-2021-4451 on NVD →

NinjaFirewall <= 4.3.3 - Authenticated PHAR Deserialization

medium

The NinjaFirewall plugin for WordPress is vulnerable to Authenticated PHAR Deserialization in versions up to, and including, 4.3.3. This allows authenticated attackers to perform phar deserialization on the server. This deserialization can allow other plugin or theme exploits if vulnerable software is present (WordPre...

CVSS:
6.6
Affected:
up to 4.3.4
Fixed in:
4.3.4
Disclosed:
May 30, 2021

CVE-2021-4451 on NVD →

NinjaFirewall (WP Edition) &#8211; Advanced Security Plugin and Firewall [ninjafirewall] < 4.3.4

unknown

Authenticated PHAR Deserialization vulnerability discovered by Chloe Chamberland in WordPress NinjaFirewall plugin (versions <= 4.3.3).

Affected:
up to 4.3.4
Fixed in:
4.3.4
Disclosed:
May 30, 2021

NinjaFirewall (WP Edition) &#8211; Advanced Security Plugin and Firewall [ninjafirewall] < 4.3.4

unknown

The NinjaFirewall plugin for WordPress is vulnerable to Authenticated PHAR Deserialization in versions up to, and including, 4.3.3. This allows authenticated attackers to perform phar deserialization on the server. This deserialization can allow other plugin or theme exploits if vulnerable software is present (WordPre...

Affected:
up to 4.3.4
Fixed in:
4.3.4
Disclosed:
May 30, 2021

NinjaFirewall (WP Edition) &#8211; Advanced Security Plugin and Firewall [ninjafirewall] < 4.3.4

unknown

The plugin was affected by a PHAR deserialisation issue, which may allow admin users to execute arbitrary code on the remote host. The plugin did not have a POP chain available, so another plugin/theme with one would need to be present, other conditions for the attack are described in the vendor&#039;s post.

Affected:
up to 4.3.4
Fixed in:
4.3.4

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database