Stored Cross-Site Scripting Vulnerability in Ninja Forms by WordPress
CVE-2025-5398
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 27 June 2025
What is CVE-2025-5398?
The Ninja Forms plugin for WordPress is susceptible to Stored Cross-Site Scripting (XSS) due to inadequate output escaping of user-supplied data in its templating engine. This flaw affects all versions up to and including 3.10.2.1. Authenticated attackers with contributor-level access can potentially exploit this vulnerability to inject and execute arbitrary scripts in the web pages, posing serious risks to users accessing those affected pages.
Affected Version(s)
Ninja Forms – The Contact Form Builder That Grows With You * <= 3.10.2.1