PHP Object Injection Vulnerability in Ninja Forms Plugin for WordPress
CVE-2026-11363
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 9 September 2026
What is CVE-2026-11363?
The Ninja Forms plugin for WordPress is susceptible to PHP Object Injection due to improper handling of user inputs during the deserialization process. This vulnerability affects all versions up to and including 3.14.6 and allows authenticated users with administrator-level access to inject a PHP Object simply by importing a specially crafted form. Although there is no inherent impact without the presence of a 'poisoned' object payload (POP chain) from an additional plugin or theme, if such a chain exists, it could enable attackers to perform harmful actions, including the deletion of files, access to sensitive information, or the execution of arbitrary code. The deserialization is executed automatically, highlighting the need for vigilant security practices when importing forms within the Ninja Forms plugin.
Affected Version(s)
Ninja Forms β The Contact Form Builder That Grows With You 0 <= 3.14.6