CVE-2025-2560: Ninja Forms < 3.10.1 - Admin+ Stored XSS
Published May 19, 2025
·Updated
The Ninja Forms WordPress plugin before 3.10.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup).
Affected Software
2 affected components
Ninja Forms Ninja Forms<3.10.1
NinjaForms Ninja Forms Wordpress<3.10.1
Event History
May 19, 2025
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·06:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-2560?
CVE-2025-2560 has a high severity rating due to its potential for Stored Cross-Site Scripting attacks.
2
How do I fix CVE-2025-2560?
To fix CVE-2025-2560, update Ninja Forms to version 3.10.1 or a later version.
3
Who is affected by CVE-2025-2560?
CVE-2025-2560 affects users of Ninja Forms on WordPress prior to version 3.10.1.
4
What type of vulnerability is CVE-2025-2560?
CVE-2025-2560 is classified as a Stored Cross-Site Scripting (XSS) vulnerability.
5
Can unprivileged users exploit CVE-2025-2560?
No, CVE-2025-2560 requires high privilege users, such as admins, to exploit the vulnerability.