Cross-Site Request Forgery in Ninja Forms Plugin for WordPress

Post Reply
Shane1145
Posts: 1689
Joined: Wed Sep 25, 2024 2:31 pm

Cross-Site Request Forgery in Ninja Forms Plugin for WordPress

Post by Shane1145 »

What is CVE-2025-10499?
The Ninja Forms plugin for WordPress is susceptible to a Cross-Site Request Forgery due to insufficient nonce validation in the maybe_opt_in() function. This flaw enables attackers to potentially opt-in the site for tracking or data collection by executing unauthorized requests. Successful exploitation requires the attacker to deceive a site administrator into interacting with a malicious link.

https://securityvulnerability.io/vulner ... 2025-10499
Post Reply