CVE-2025-5398: Ninja Forms <= 3.10.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via CSTI
The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the use of a templating engine in all versions up to, and including, 3.10.2.1 due to insufficient output escaping on user data passed through the template. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-5398?
CVE-2025-5398 is considered a high-severity vulnerability due to the potential for stored cross-site scripting attacks.
How do I fix CVE-2025-5398?
To fix CVE-2025-5398, update the Ninja Forms plugin to version 3.10.2.2 or higher where the vulnerability has been patched.
What is the impact of CVE-2025-5398?
The impact of CVE-2025-5398 allows attackers to execute arbitrary scripts in the context of an affected user's browser.
Which versions of Ninja Forms are affected by CVE-2025-5398?
All versions of Ninja Forms up to and including 3.10.2.1 are affected by CVE-2025-5398.
Is user data at risk with CVE-2025-5398?
Yes, CVE-2025-5398 puts user data at risk as it allows for stored cross-site scripting on improperly escaped user inputs.