- Description
- The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.12.0. This is due to missing or incorrect nonce validation when exporting CSV files. This makes it possible for unauthenticated attackers to delete those files granted they can trick an administrator into performing an action such as clicking on a link.
- Source
- security@wordfence.com
- NVD status
- Analyzed
- Products
- ninja_forms
CVSS 3.1
- Type
- Primary
- Base score
- 5.4
- Impact score
- 2.5
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
- Severity
- MEDIUM
- security@wordfence.com
- CWE-352
- Hype score
- Not currently trending
CVE-2025-10498 Cross-Site Request Forgery in Ninja Forms WordPress Plugin Versions ≤ 3.12.0 https://t.co/7GldAxjAoY
@VulmonFeeds
27 Sept 2025
6 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-10498 The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.12… https://t.co/bpuqR6ca5J
@CVEnew
27 Sept 2025
447 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:ninjaforms:ninja_forms:*:*:*:*:*:wordpress:*:*",
"matchCriteriaId": "9182CBC2-A77D-468A-B3DA-B25F9EC83AA1",
"versionEndExcluding": "3.12.1",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]