Missing Authorization Vulnerability in Ninja Forms WordPress Plugin
CVE-2026-65050

7.1HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
21 July 2026

What is CVE-2026-65050?

The Ninja Forms plugin for WordPress has a vulnerability that permits authenticated attackers with Author-level privileges to expose confidential form submissions to the public. This occurs through a render callback in the 'ninja-forms/submissions-table' Gutenberg block. By embedding this block with an arbitrary formID in published posts, attackers can retrieve sensitive information stored within the submissions. The attack can be executed by leveraging a signed bearer token present in browser sessions, which allows unauthorized access to the REST API submissions endpoint, revealing personally identifiable information such as names, email addresses, and phone numbers.

Affected Version(s)

Ninja Forms 0

Ninja Forms 0 < 3.14.9

Ninja Forms 3.14.9

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Pavel Kohout
.