CVE-2025-9083: Ninjaforms Ninja Forms

Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.

The Ninja Forms WordPress plugin before 3.11.1 unserializes user input via form field, which could allow Unauthenticated users to perform PHP Object Injection when a suitable gadget is present on the blog.

Affected products

  • Ninjaforms Ninja Forms: before 3.11.1 (fixed in 3.11.1)

Published 2025-09-18. Last modified 2026-06-17.