cleantalk
Vulnerabilities and Security Researches

Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress, CVE-2026-1239

CVE, Research URL

CVE-2026-1239

Published on
Jul 01, 2026
Research Description
The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to unauthorized access of data due to a missing authorization check on the 'ninja-forms-views/token/refresh' REST callback in all versions up to, and including, 3.14.1. This makes it possible for unauthenticated attackers to view form submissions, which could potentially contain sensitive information.
Affected versions
max 3.14.2.
Status
vulnerable