Server-Side Security Bypass in Ninja Forms WordPress Plugin
CVE-2026-65051

6.9MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
21 July 2026

What is CVE-2026-65051?

A flaw in the Ninja Forms WordPress plugin version 3.14.8 allows unauthorized users to bypass server-side security checks by manipulating client-side data. Attackers can exploit this vulnerability via the nopriv AJAX endpoint to send crafted submissions that override the intended field definitions. This can lead to unauthorized actions such as sending email notifications and storing unvalidated data in the database. The attacker-controlled metadata can remove critical validation checks, exposing the application to potential data leaks and malicious activity.

Affected Version(s)

Ninja Forms 0

Ninja Forms 0 < 3.14.9

Ninja Forms 3.14.9

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Pavel Kohout
.