cleantalk
Vulnerabilities and Security Researches

Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress, CVE-2025-9083

CVE, Research URL

CVE-2025-9083

Published on
Sep 18, 2025
Research Description
The Ninja Forms WordPress plugin before 3.11.1 unserializes user input via form field, which could allow Unauthenticated users to perform PHP Object Injection when a suitable gadget is present on the blog.
Affected versions
max 3.11.1.
Status
vulnerable