PT-2025-38301 · WordPress · Ninja Forms

Wcraft

·

Published

2025-09-18

·

Updated

2025-09-26

·

CVE-2025-9083

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ninja Forms WordPress plugin versions prior to 3.11.1
Description The Ninja Forms WordPress plugin is susceptible to PHP Object Injection due to the unserialization of user-supplied data through form fields. This allows unauthenticated users to potentially execute malicious payloads.
Recommendations Update Ninja Forms to version 3.11.1 or later.

Exploit

Fix

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

CVE-2025-9083

Affected Products

Ninja Forms