Insecure Direct Object Reference in Ninja Forms - Excel Export Plugin for WordPress
CVE-2026-15159
4.3MEDIUM
What is CVE-2026-15159?
The Ninja Forms - Excel Export plugin for WordPress is vulnerable to an Insecure Direct Object Reference due to insufficient validation of the 'spreadsheet_export_form_id' parameter. Authenticated users with subscriber-level access and higher can exploit this flaw to gain unauthorized access to any Ninja Forms forms. This allows attackers to enumerate form IDs and download sensitive submission data, including personally identifiable information (PII) like names, email addresses, and phone numbers in a downloadable XLSX format.
Affected Version(s)
Ninja Forms - Excel Export 0 <= 3.3.6