CVE-2025-2524: Ninja Forms < 3.10.1 - Admin+ Stored XSS
The Ninja Forms WordPress plugin before 3.10.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-2524?
The severity of CVE-2025-2524 is considered high due to its potential for allowing Stored Cross-Site Scripting attacks.
How do I fix CVE-2025-2524?
To fix CVE-2025-2524, update the Ninja Forms plugin to version 3.10.1 or later.
Who is affected by CVE-2025-2524?
High privilege users, such as administrators in WordPress, are primarily affected by CVE-2025-2524.
Can CVE-2025-2524 be exploited in a multisite setup?
Yes, CVE-2025-2524 can be exploited in a multisite setup even when the unfiltered_html capability is disallowed.
What types of attacks are possible with CVE-2025-2524?
CVE-2025-2524 allows for Stored Cross-Site Scripting attacks due to insufficient sanitization and escaping of settings.