PT-2025-38301 · WordPress · Ninja Forms

·

CVE-2025-9083

·

Published

2025-09-18

·

Updated

2025-09-26

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ninja Forms WordPress plugin versions prior to 3.11.1
Description The Ninja Forms WordPress plugin is susceptible to PHP Object Injection due to the unserialization of user-supplied data through form fields. This allows unauthenticated users to potentially execute malicious payloads.
Recommendations Update Ninja Forms to version 3.11.1 or later.

Exploit

Fix

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-9083

Affected Products

Ninja Forms