CVE-2025-2524 | Ninja Forms Plugin up to 3.10.0 on WordPress Setting cross site scripting (EUVD-2025-15656)
A vulnerability has been found in Ninja Forms Plugin up to 3.10.0 on WordPress and classified as problematic. This affects an unknown function of the component Setting Handler. The manipulation leads to cross site scripting.
This vulnerability is referenced as CVE-2025-2524. Remote exploitation of the attack is possible. No exploit is available.
The affected component should be upgraded.