First published: Fri Apr 04 2025(Updated: )
Cross-Site Request Forgery (CSRF) vulnerability in CRM Perks WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms allows Cross Site Request Forgery. This issue affects WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms: from n/a through 1.1.3.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
CRM Perks WP Zendesk for Contact Form 7 | <=1.1.3 | |
WPForms | <=1.1.3 | |
CRM Perks Elementor | <=1.1.3 | |
CRM Perks Formidable | <=1.1.3 | |
CRM Perks Ninja Forms | <=1.1.3 |
Update the WordPress WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms wordpress plugin to the latest available version (at least 1.1.4).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-32269 is classified as a moderate severity Cross-Site Request Forgery (CSRF) vulnerability.
To mitigate CVE-2025-32269, update the affected plugins, WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable, and Ninja Forms, to version 1.1.4 or later.
CVE-2025-32269 affects versions 1.1.3 and lower of WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable, and Ninja Forms.
CVE-2025-32269 can enable attackers to perform unauthorized actions on behalf of authenticated users due to Cross-Site Request Forgery.
Users of the CRM Perks WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable, and Ninja Forms plugins are primarily impacted by CVE-2025-32269.