CVE-2025-10498: Ninja Forms – The Contact Form Builder That Grows With You <= 3.12.0 - Cross-Site Request Forgery to Limited File Deletion
The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.12.0. This is due to missing or incorrect nonce validation when exporting CSV files. This makes it possible for unauthenticated attackers to delete those files granted they can trick an administrator into performing an action such as clicking on a link.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-10498?
CVE-2025-10498 is considered a high severity vulnerability due to its potential for exploitation via Cross-Site Request Forgery.
How do I fix CVE-2025-10498?
To fix CVE-2025-10498, you should update the Ninja Forms plugin to version 3.12.1 or later.
What versions are affected by CVE-2025-10498?
CVE-2025-10498 affects all versions of the Ninja Forms plugin up to and including version 3.12.0.
What type of vulnerability is CVE-2025-10498?
CVE-2025-10498 is a Cross-Site Request Forgery (CSRF) vulnerability.
Who is affected by CVE-2025-10498?
Users of the Ninja Forms plugin for WordPress who have versions up to 3.12.0 installed are affected by CVE-2025-10498.