CVE-2016-1209: Ninjaforms Ninja Forms

Critical severity, CVSS 9.8. EPSS: 61.6% chance of exploitation in the next 30 days.

The Ninja Forms plugin before 2.9.42.1 for WordPress allows remote attackers to conduct PHP object injection attacks via crafted serialized values in a POST request.

Affected products

  • Ninjaforms Ninja Forms: up to and including 2.9.42

Published 2016-05-14. Last modified 2026-06-17.