PHP Object Injection Vulnerability in Ninja Forms Plugin for WordPress
CVE-2026-11363

6.6MEDIUM

What is CVE-2026-11363?

The Ninja Forms plugin for WordPress is susceptible to PHP Object Injection due to improper handling of user inputs during the deserialization process. This vulnerability affects all versions up to and including 3.14.6 and allows authenticated users with administrator-level access to inject a PHP Object simply by importing a specially crafted form. Although there is no inherent impact without the presence of a 'poisoned' object payload (POP chain) from an additional plugin or theme, if such a chain exists, it could enable attackers to perform harmful actions, including the deletion of files, access to sensitive information, or the execution of arbitrary code. The deserialization is executed automatically, highlighting the need for vigilant security practices when importing forms within the Ninja Forms plugin.

Affected Version(s)

Ninja Forms – The Contact Form Builder That Grows With You 0 <= 3.14.6

References

CVSS V3.1

Score:
6.6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Hermione
.