The Ninja Forms WordPress plugin before 3.10.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
We have discovered 44,999 live websites that are affected by CVE-2025-2561.
| Product | |
| Category | Form Builders |
| Vulnerable Domains | 44,999 live websites (34% of Ninja Forms install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 212 versions ( 91% of all versions) |
| 17,406 websites | |
| 4,343 websites | |
| 3,086 websites | |
| 2,663 websites | |
| 1,563 websites | |
| 1,412 websites | |
| 1,201 websites | |
| 1,172 websites | |
| 970 websites | |
| 668 websites |
| .com | 21,165 websites |
| .org | 2,430 websites |
| .de | 2,409 websites |
| .co.uk | 2,165 websites |
| .nl | 1,444 websites |
| .fr | 1,215 websites |
| .com.au | 1,090 websites |
| .net | 1,003 websites |
| .it | 937 websites |
| .ca | 664 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| **********.com | *,*** | ||
| ****************.com | *,*** | ||
| ****************.com | *,*** | ||
| ************.com | **,*** | ||
| **********.ro | **,*** | ||
| **************.com | **,*** | ||
| **************.com | **,*** | ||
| *******.**.il | **,*** | ||
| *****************.fr | **,*** | ||
| ************.org | **,*** |
FAQ