CVE-2024-25572

Cross-site request forgery (CSRF) vulnerability exists in Ninja Forms prior to 3.4.31. If a website administrator views a malicious page while logging in, unintended operations may be performed.
Configurations

Configuration 1 (hide)

cpe:2.3:a:ninjaforms:ninja_forms:*:*:*:*:*:wordpress:*:*

History

08 Apr 2025, 15:17

Type Values Removed Values Added
First Time Ninjaforms ninja Forms
Ninjaforms
References () https://jvn.jp/en/jp/JVN50361500/ - () https://jvn.jp/en/jp/JVN50361500/ - Third Party Advisory
References () https://ninjaforms.com/ - () https://ninjaforms.com/ - Product
References () https://wordpress.org/plugins/ninja-forms/ - () https://wordpress.org/plugins/ninja-forms/ - Product
CPE cpe:2.3:a:ninjaforms:ninja_forms:*:*:*:*:*:wordpress:*:*

13 Mar 2025, 15:15

Type Values Removed Values Added
CWE CWE-352

21 Nov 2024, 09:01

Type Values Removed Values Added
References () https://jvn.jp/en/jp/JVN50361500/ - () https://jvn.jp/en/jp/JVN50361500/ -
References () https://ninjaforms.com/ - () https://ninjaforms.com/ -
References () https://wordpress.org/plugins/ninja-forms/ - () https://wordpress.org/plugins/ninja-forms/ -

03 Jul 2024, 01:49

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8

11 Apr 2024, 12:47

Type Values Removed Values Added
Summary
  • (es) Vulnerabilidad de Cross-site request forgery (CSRF) existe en Ninja Forms antes de la versión 3.4.31. Si un administrador de un sitio web ve una página maliciosa mientras inicia sesión, se pueden realizar operaciones no deseadas.

11 Apr 2024, 03:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-04-11 03:15

Updated : 2025-04-08 15:17


NVD link : CVE-2024-25572

Mitre link : CVE-2024-25572

CVE.ORG link : CVE-2024-25572


JSON object : View

Products Affected

ninjaforms

  • ninja_forms
CWE
CWE-352

Cross-Site Request Forgery (CSRF)