← volver
CVE-2025-9083

Ninja-forms < 3.11.1 - Unauthenticated PHP Objection

CVSS 9.8 CRITICALEPSS 0.5%
The Ninja Forms WordPress plugin before 3.11.1 unserializes user input via form field, which could allow Unauthenticated users to perform PHP Object Injection when a suitable gadget is present on the blog.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Productos afectados
Unknown · Ninja Forms

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →