CVE 9.8 CRITICAL

Ninja-forms < 3.11.1 - Unauthenticated PHP Objection_CVE-2025-9083

9.8 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

The Ninja Forms WordPress plugin before 3.11.1 unserializes user input via form field, which could allow Unauthenticated users to perform PHP Object Injection when a suitable gadget is present on the blog.

Basic Information

ID CVE-2025-9083
Source WPScan
Published Sep 18, 2025 at 06:00
Modified Sep 22, 2025 at 17:27

Affected Product

Vendor Unknown
Product Ninja Forms
Affected Versions Unknown Ninja Forms 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.