Missing Authorization Vulnerability in Ninja Forms WordPress Plugin
CVE-2026-65050
7.1HIGH
What is CVE-2026-65050?
The Ninja Forms plugin for WordPress has a vulnerability that permits authenticated attackers with Author-level privileges to expose confidential form submissions to the public. This occurs through a render callback in the 'ninja-forms/submissions-table' Gutenberg block. By embedding this block with an arbitrary formID in published posts, attackers can retrieve sensitive information stored within the submissions. The attack can be executed by leveraging a signed bearer token present in browser sessions, which allows unauthorized access to the REST API submissions endpoint, revealing personally identifiable information such as names, email addresses, and phone numbers.
Affected Version(s)
Ninja Forms 0
Ninja Forms 0 < 3.14.9
Ninja Forms 3.14.9