PT-2025-39706 · WordPress · Ninja Forms – The Contact Form Builder That Grows With You

Published

2025-09-27

·

Updated

2025-09-27

·

CVE-2025-10499

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress versions prior to 3.12.1
Description The software is susceptible to a Cross-Site Request Forgery (CSRF) issue. This is caused by inadequate or missing nonce validation within the maybe opt in() function. An unauthenticated attacker could potentially force an affected site to enable usage statistics collection by deceiving a site administrator into performing an action, such as clicking a link.
Recommendations Update Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress to version 3.12.1 or later.

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2025-10499

Affected Products

Ninja Forms – The Contact Form Builder That Grows With You