Access Control Flaw in Ninja Forms Plugin by WordPress
CVE-2026-80438

Currently unrated

Key Information:

Vendor

WordPress

Vendor
CVE Published:
4 September 2026

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2026-80438?

The Ninja Forms plugin for WordPress, up to version 3.15.2, has a significant access control issue that allows unauthorized users with specific capabilities to access sensitive data. This vulnerability enables such users to read the plugin's configuration settings and stored form submissions. Furthermore, it permits them to modify settings and create or change any posts or pages, effectively giving them elevated administrative powers, which are not ordinarily assigned to default WordPress roles. Administrators are only affected if they delegate this privileged access carelessly.

Affected Version(s)

Ninja Forms 3.14.0 < 3.15.2

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

ChinhNguyen
WPScan
.