Access Control Flaw in Ninja Forms Plugin by WordPress
CVE-2026-80438
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 4 September 2026
Badges
What is CVE-2026-80438?
The Ninja Forms plugin for WordPress, up to version 3.15.2, has a significant access control issue that allows unauthorized users with specific capabilities to access sensitive data. This vulnerability enables such users to read the plugin's configuration settings and stored form submissions. Furthermore, it permits them to modify settings and create or change any posts or pages, effectively giving them elevated administrative powers, which are not ordinarily assigned to default WordPress roles. Administrators are only affected if they delegate this privileged access carelessly.
Affected Version(s)
Ninja Forms 3.14.0 < 3.15.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.