PT-2025-39705 · WordPress · Ninja Forms

CVE-2025-10498

·

Publicado

2025-09-27

·

Atualizado

2025-09-27

CVSS v3.1

5.4

Média

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions Ninja Forms – The Contact Form Builder That Grows With You versions prior to 3.12.1
Description The software is susceptible to Cross-Site Request Forgery (CSRF) due to inadequate nonce validation when exporting CSV files. This allows unauthenticated attackers to delete CSV files if they can trick an administrator into performing an action, such as clicking a malicious link.
Recommendations Update Ninja Forms – The Contact Form Builder That Grows With You to version 3.12.1 or later.

Correção

CSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-10498

Produtos afetados

Ninja Forms