Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress, CVE-2026-65050
- CVE, Research URL
- Home page URL
-
Security reports for Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress
- Published on
- Jul 21, 2026
- Research Description
- Ninja Forms WordPress plugin version 3.14.8 and prior contains a missing authorization vulnerability in the render callback of the `ninja-forms/submissions-table` Gutenberg block that allows authenticated attackers with Author-level privileges to expose stored form submissions to unauthenticated visitors by embedding the block with an arbitrary formID on a published post. Attackers can retrieve the signed bearer token injected into every page visitor's browser via `wp_localize_script` and use it against the REST API submissions endpoint to access all saved form submission field values, including sensitive personally identifiable information such as names, email addresses, and phone numbers.
- Affected versions
-
max 3.14.8.
- Status
-
vulnerable