CVE-2025-9083

Severity
9.8CRITICAL
EPSS
0.3%
top 42.99%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 18

Description

The Ninja Forms WordPress plugin before 3.11.1 unserializes user input via form field, which could allow Unauthenticated users to perform PHP Object Injection when a suitable gadget is present on the blog.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages2 packages

CVEListV5unknown/ninja_forms< 3.11.1

🔴Vulnerability Details

2
CVEList
Ninja-forms < 3.11.1 - Unauthenticated PHP Objection2025-09-18
GHSA
GHSA-q88q-7pp2-q72v: The Ninja Forms WordPress plugin before 32025-09-18