PT-2025-39705 · WordPress · Ninja Forms

Published

2025-09-27

·

Updated

2025-09-27

·

CVE-2025-10498

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions Ninja Forms – The Contact Form Builder That Grows With You versions prior to 3.12.1
Description The software is susceptible to Cross-Site Request Forgery (CSRF) due to inadequate nonce validation when exporting CSV files. This allows unauthenticated attackers to delete CSV files if they can trick an administrator into performing an action, such as clicking a malicious link.
Recommendations Update Ninja Forms – The Contact Form Builder That Grows With You to version 3.12.1 or later.

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2025-10498

Affected Products

Ninja Forms