Website support, maintenance and fixes for UK businessesCall 0208 088 8371info@websupportservices.co.uk

HomeWordPress vulnerabilitiesNinja Forms

Ninja Forms vulnerabilities

Ninja Forms has 66 known vulnerabilities in this database. The most recent published record is dated 2 Oct 2026.

Known vulnerabilities
66
Active installs
600,000+
Latest version
3.15.5
Last updated
28 Sep 2026
Most recent
2 Oct 2026

Find it in your WordPress dashboard under Plugins. Severity is based on the CVSS score published with the CVE where one is available.

VulnerabilitySeverityAffectedFixPublished
Cross-site scripting (XSS)
CVE-2026-90438
High 7.2Up to 3.15.4Fixed in a later version (latest 3.15.5)5 d ago
Remote code execution
CVE-2026-91827
High 7.5Not yet publishedCheck for an update22 Sep 2026
Cross-site scripting (XSS)
CVE-2026-92438
High 8.8Not yet publishedCheck for an update22 Sep 2026
Cross-site scripting (XSS)
CVE-2026-94504
High 7.2Not yet publishedCheck for an update22 Sep 2026
PHP object injection
CVE-2026-11363
Medium 6.6Up to 3.14.6Fixed in a later version (latest 3.15.5)9 Sep 2026
Security weakness
CVE-2026-80437
Medium 4.8Before 3.15.2Fixed in 3.15.26 Sep 2026
Cross-site scripting (XSS)
CVE-2026-19769
High 7.2Up to 3.15.1Fixed in a later version (latest 3.15.5)5 Sep 2026
Broken access control
CVE-2026-80438
Medium 5.9Before 3.15.2Fixed in 3.15.24 Sep 2026
Security weakness
CVE-2026-15256
Medium 4.8Before 3.14.10Fixed in 3.14.106 Aug 2026
SQL injection
CVE-2026-15663
Medium 4.9Up to 3.14.9Fixed in a later version (latest 3.15.5)24 Jul 2026
Broken access control
CVE-2026-65050
Medium 6.5Not yet publishedCheck for an update21 Jul 2026
Security weakness
CVE-2026-65051
Medium 6.5Not yet publishedCheck for an update21 Jul 2026
Security weakness
CVE-2026-65052
High 7.5Not yet publishedCheck for an update21 Jul 2026
Cross-site scripting (XSS)
CVE-2026-65048
Critical 9.3Up to 3.14.9Fixed in a later version (latest 3.15.5)21 Jul 2026
Broken access control
CVE-2026-65049
Critical 9.3Not yet publishedCheck for an update21 Jul 2026
Broken access control
CVE-2026-1239
High 7.5Up to 3.14.1Fixed in a later version (latest 3.15.5)1 Jul 2026
Sensitive data exposure
CVE-2026-1307
Medium 6.5Up to 3.14.1Fixed in a later version (latest 3.15.5)28 Mar 2026
Sensitive data exposure
CVE-2026-2268
High 7.5Up to 3.14.0Fixed in a later version (latest 3.15.5)10 Feb 2026
Security weakness
CVE-2025-14072
Medium 5.3Before 3.13.3Fixed in 3.13.32 Jan 2026
Broken access control
CVE-2025-11924
High 7.5Before 3.13.1Fixed in 3.13.117 Dec 2025
Cross-site request forgery (CSRF)
CVE-2025-10499
Medium 4.3Before 3.12.1Fixed in 3.12.127 Sep 2025
Cross-site request forgery (CSRF)
CVE-2025-10498
Medium 4.3Before 3.12.1Fixed in 3.12.127 Sep 2025
PHP object injection
CVE-2025-9083
Critical 9.8Before 3.11.1Fixed in 3.11.118 Sep 2025
Cross-site scripting (XSS)
CVE-2025-5398
Medium 6.4Before 3.10.2.2Fixed in 3.10.2.227 Jun 2025
Cross-site scripting (XSS)
CVE-2025-2524
Medium 4.8Before 3.10.1Fixed in 3.10.119 May 2025
Cross-site scripting (XSS)
CVE-2025-2560
Medium 4.8Before 3.10.1Fixed in 3.10.119 May 2025
Cross-site scripting (XSS)
CVE-2025-2561
Medium 4.8Before 3.10.1Fixed in 3.10.119 May 2025
Cross-site scripting (XSS)
CVE-2024-13470
Medium 6.4Before 3.8.25Fixed in 3.8.2530 Jan 2025
Remote code execution
CVE-2024-12238
Medium 6.3Before 3.8.23Fixed in 3.8.2329 Dec 2024
Cross-site scripting (XSS)
CVE-2024-11052
High 7.2Before 3.8.20Fixed in 3.8.2012 Dec 2024
Cross-site scripting (XSS)
CVE-2024-3866
Medium 4.7Before 3.8.16Fixed in 3.8.1625 Sep 2024
Cross-site scripting (XSS)
CVE-2024-7354
Medium 6.1Before 3.8.11Fixed in 3.8.112 Sep 2024
Cross-site scripting (XSS)
CVE-2024-2108
Medium 4.6Before 3.8.1Fixed in 3.8.129 Mar 2024
Cross-site request forgery (CSRF)
CVE-2024-2113
Medium 4.3Before 3.8.1Fixed in 3.8.129 Mar 2024
SQL injection
CVE-2024-0685
Medium 5.9Up to 3.7.1Fixed in a later version (latest 3.15.5)2 Feb 2024
Denial of service
CVE-2023-35909
Medium 5.3Before 3.6.26Fixed in 3.6.267 Dec 2023
Cross-site scripting (XSS)
CVE-2023-5530
Medium 4.8Before 3.6.34Fixed in 3.6.346 Nov 2023
Cross-site scripting (XSS)
CVE-2023-1835
Medium 6.1Before 3.6.22Fixed in 3.6.2215 May 2023
PHP object injection
CVE-2022-2903
High 7.2Before 3.6.13Fixed in 3.6.1326 Sep 2022
Cross-site scripting (XSS)
CVE-2021-25056
Medium 4.8Before 3.6.10Fixed in 3.6.104 Jul 2022
Cross-site scripting (XSS)
CVE-2021-25066
Medium 4.8Before 3.6.10Fixed in 3.6.104 Jul 2022
Cross-site scripting (XSS)
CVE-2021-36827
Medium 4.8Up to 3.6.9Fixed in a later version (latest 3.15.5)16 Jun 2022
SQL injection
CVE-2021-24889
High 7.2Before 3.6.4Fixed in 3.6.429 Nov 2021
Sensitive data exposure
CVE-2021-34647
Medium 6.5Up to 3.5.7Fixed in a later version (latest 3.15.5)22 Sep 2021
Broken access control
CVE-2021-34648
Medium 6.4Up to 3.5.7Fixed in a later version (latest 3.15.5)22 Sep 2021
Sensitive data exposure
CVE-2021-24163
High 8.8Before 3.4.34Fixed in 3.4.345 Apr 2021
Sensitive data exposure
CVE-2021-24164
Medium 4.3Before 3.4.34.1Fixed in 3.4.34.15 Apr 2021
Open redirect
CVE-2021-24165
Medium 6.1Before 3.4.34Fixed in 3.4.345 Apr 2021
Cross-site request forgery (CSRF)
CVE-2021-24166
Medium 5.4Before 3.4.34Fixed in 3.4.345 Apr 2021
Security weakness
CVE-2020-36173
Medium 5.3Before 3.4.28Fixed in 3.4.286 Jan 2021
Cross-site request forgery (CSRF)
CVE-2020-36174
Medium 6.5Before 3.4.27.1Fixed in 3.4.27.16 Jan 2021
Security weakness
CVE-2020-36175
Medium 5.3Before 3.4.27.1Fixed in 3.4.27.16 Jan 2021
Cross-site scripting (XSS)
CVE-2020-12462
Medium 6.1Before 3.4.24.2Fixed in 3.4.24.229 Apr 2020
Cross-site scripting (XSS)
CVE-2020-8594
Medium 5.4Not yet publishedCheck for an update14 Feb 2020
Security weakness
CVE-2017-18574
Medium 6.1Before 3.0.31Fixed in 3.0.3122 Aug 2019
Security weakness
CVE-2018-20980
High 7.5Before 3.2.15Fixed in 3.2.1522 Aug 2019
Security weakness
CVE-2018-20981
Critical 9.1Before 3.3.9Fixed in 3.3.922 Aug 2019
SQL injection
CVE-2019-15025
Critical 9.8Before 3.3.21.2Fixed in 3.3.21.214 Aug 2019
Arbitrary file upload
CVE-2019-10869
High 8.1Before 3.0.23Fixed in 3.0.237 May 2019
Open redirect
CVE-2018-19796
Medium 6.1Before 3.3.19.1Fixed in 3.3.19.13 Dec 2018
Cross-site scripting (XSS)
CVE-2018-19287
Medium 6.1Before 3.3.18Fixed in 3.3.1815 Nov 2018
CSV injection
CVE-2018-16308
High 8.6Before 3.3.14.1Fixed in 3.3.14.11 Sep 2018
Cross-site scripting (XSS)
CVE-2018-7280
Medium 6.1Before 3.2.14Fixed in 3.2.1421 Feb 2018
PHP object injection
CVE-2016-1209
Critical 9.8Up to 2.9.42Fixed in a later version (latest 3.15.5)14 May 2016
Cross-site scripting (XSS)
CVE-2015-2220
Not scoredUp to 2.8.8Fixed in a later version (latest 3.15.5)5 Mar 2015
Security weakness
CVE-2014-9688
Not scoredUp to 2.8.9Fixed in a later version (latest 3.15.5)5 Mar 2015
Read the published descriptions
CVE-2026-90438, 2 Oct 2026
The Ninja Forms - The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Paragraph Text (RTE) Field Submission in all versions up to, and including, 3.15.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is only exploitable when the targeted Paragraph Text field has the Rich Text Editor (RTE) option enabled. CVE record
CVE-2026-91827, 22 Sep 2026
The Ninja Forms WordPress plugin 3.15.3 does not prevent user-submitted form field values from being deserialised when an administrator later exports form submissions to CSV, allowing unauthenticated attackers to perform PHP Object Injection; if a suitable POP chain is present via another installed plugin or theme, this can lead to actions such as arbitrary file operations or remote code execution. CVE record
CVE-2026-92438, 22 Sep 2026
The Ninja Forms WordPress plugin 3.15.3 does not escape submitted form field values before outputting them on the submission edit screen in the admin area, which could allow unauthenticated users to submit values through a public form that then execute in the browser of any high-privileged user who reviews the submission. CVE record
CVE-2026-94504, 22 Sep 2026
Ninja Forms 3.15.3 stores an anonymous non-RTE textarea value and renders it without safe HTML encoding in the legacy submission editor. An attacker can break out of the textarea with stored script. When an Administrator opens the attacker-known direct submission URL, the script runs in the WordPress admin origin. CVE record
CVE-2026-11363, 9 Sep 2026
The Ninja Forms - The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.14.6 via deserialization of untrusted input . This makes it possible for authenticated attackers, with administrator-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target system, it may allow the attacker to perform actions like delete arbitrary files, retrieve sensitive data, or execute code depending on the POP chain present. The deserialization is triggered automatically during form import when WPN_Helper::build_nf_cache() invokes $action->get_settings() immediately after the crafted form is imported, requiring no further interaction beyond the import action itself. CVE record
CVE-2026-80437, 6 Sep 2026
The Ninja Forms WordPress plugin from 3.14.10 before 3.15.2 does not prevent shortcodes in request-derived values from being executed when it substitutes them into content it later processes for shortcodes, allowing unauthenticated users to run any shortcode registered on the site. CVE record
CVE-2026-19769, 5 Sep 2026
The Ninja Forms - The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Repeater Child 'type' Confusion via Unmatched Array Key in all versions up to, and including, 3.15.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires the Ninja Forms File Uploads add-on to be active, as the attack routes the unwhitelisted child entry through the File Uploads handler to write an attacker-supplied HTML file containing arbitrary JavaScript into any web-server-writable directory, including the site root, where it is served from the site's own origin. CVE record
CVE-2026-80438, 4 Sep 2026
The Ninja Forms WordPress plugin before 3.15.2 does not restrict its REST abilities to administrators, accepting a Ninja Forms WordPress plugin before 3.15.2-specific capability as equivalent to full site administration, which allows any user granted that capability to read Ninja Forms WordPress plugin before 3.15.2 settings and stored form submissions, overwrite the Ninja Forms WordPress plugin before 3.15.2's configuration, and create or modify arbitrary posts and pages. The capability belongs to no default WordPress role and the Ninja Forms WordPress plugin before 3.15.2 never grants it, so an administrator must have assigned it, typically when delegating access to the form builder. CVE record
CVE-2026-15256, 6 Aug 2026
The Ninja Forms WordPress plugin before 3.14.10 does not prevent user-supplied query-string input, used to pre-populate a form field's default value, from being processed as a shortcode, allowing unauthenticated attackers to execute arbitrary shortcodes registered on the site when a form so configured is embedded on a public page. CVE record
CVE-2026-15663, 24 Jul 2026
The Ninja Forms - The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to generic SQL Injection via Import File 'settings' Key in all versions up to, and including, 3.14.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. The vulnerable keys originate from the 'settings' object in an attacker-controlled import file processed via file_get_contents() or base64-decoded/JSON-decoded blobs, bypassing wp_magic_quotes protections entirely; two distinct sinks are affected - _save_setting() in Model.php and insert_form_meta() in ImportForm.php - as only the value side is escaped while the key side receives no sanitization or parameterization at any point in the call chain. CVE record
CVE-2026-65050, 21 Jul 2026
Ninja Forms WordPress plugin version 3.14.8 and prior contains a missing authorization vulnerability in the render callback of the `ninja-forms/submissions-table` Gutenberg block that allows authenticated attackers with Author-level privileges to expose stored form submissions to unauthenticated visitors by embedding the block with an arbitrary formID on a published post. Attackers can retrieve the signed bearer token injected into every page visitor's browser via `wp_localize_script` and use it against the REST API submissions endpoint to access all saved form submission field values, including sensitive personally identifiable information such as names, email addresses, and phone numbers. CVE record
CVE-2026-65051, 21 Jul 2026
Ninja Forms WordPress plugin version 3.14.8 contains a client-side enforcement of server-side security vulnerability that allows unauthenticated attackers to bypass all form validation by merging attacker-controlled field metadata over server-loaded form definitions before validation runs. Attackers can craft a malicious AJAX submission overriding field types, removing required flags, and disabling CAPTCHA checks through the nopriv AJAX endpoint to trigger form actions such as email notifications and database storage with unverified, attacker-controlled content. CVE record
CVE-2026-65052, 21 Jul 2026
Ninja Forms WordPress plugin version 3.14.8 and prior contains an improper input validation vulnerability that allows unauthenticated attackers to inject arbitrary numeric values into form calculations and payment totals by submitting values that do not match any configured option in ListSelect or ListRadio fields. Attackers can tamper with form submission payloads to the ajax submit endpoint, causing the get_calc_value() method to fail open and return attacker-controlled values, enabling manipulation of payment amounts to zero or arbitrary figures and bypassing admin-configured pricing logic. CVE record
CVE-2026-65048, 21 Jul 2026
Ninja Forms plugin for WordPress versions 3.10.4 through 3.14.9 contains an unauthenticated stored cross-site scripting vulnerability in the Repeatable Fieldset feature where parseSubmissionIndex() accepts arbitrary strings as submission indexes without numeric validation, and admin_form_element() interpolates the index directly into HTML without escaping. An unauthenticated attacker can submit a public form with a crafted repeater child key containing malicious script payloads, which execute in an administrator's browser when viewing submissions in the WordPress admin panel, enabling session-cookie theft, creation of administrator accounts, installation of malicious plugins, and arbitrary modification of site content. CVE record
CVE-2026-65049, 21 Jul 2026
Ninja Forms plugin version 3.14.8 and prior for WordPress Multisite contains an incorrect authorization vulnerability that allows a subsite Administrator to trigger network-wide deletion of all Ninja Forms data by exploiting a site-scoped capability check combined with unsafe multisite migration defaults. Attackers can send a crafted POST request to the admin-ajax.php endpoint with the nf_delete_all_data action and a per-site nonce to invoke migration routines that unconditionally iterate all blogs via switch_to_blog(), dropping all nf3_* tables and clearing options and transients across every subsite in the network without requiring super-admin or network-admin privileges. CVE record
CVE-2026-1239, 1 Jul 2026
The Ninja Forms - The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to unauthorized access of data due to a missing authorization check on the 'ninja-forms-views/token/refresh' REST callback in all versions up to, and including, 3.14.1. This makes it possible for unauthenticated attackers to view form submissions, which could potentially contain sensitive information. CVE record
CVE-2026-1307, 28 Mar 2026
The Ninja Forms - The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.14.1 via a callback function for the admin_enqueue_scripts action handler in blocks/bootstrap.php. This makes it possible for authenticated attackers, with Contributor-level access and above, to gain access to an authorization token to view form submissions for arbitrary forms, which could potentially contain sensitive information. CVE record
CVE-2026-2268, 10 Feb 2026
The Ninja Forms plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.14.0. This is due to the unsafe application of the `ninja_forms_merge_tags` filter to user-supplied input within repeater fields, which allows the resolution of `{post_meta:KEY}` merge tags without authorization checks. This makes it possible for unauthenticated attackers to extract arbitrary post metadata from any post on the site, including sensitive data such as WooCommerce billing emails, API keys, private tokens, and customer personal information via the `nf_ajax_submit` AJAX action. CVE record
CVE-2025-14072, 2 Jan 2026
The Ninja Forms WordPress plugin before 3.13.3 allows unauthenticated attackers to generate valid access tokens via the REST API which can then be used to read form submissions. CVE record
CVE-2025-11924, 17 Dec 2025
The Ninja Forms - The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.13.2. This is due to the plugin not properly verifying that a user is authorized before the `ninja-forms-views` REST endpoints return form metadata and submission content. This makes it possible for unauthenticated attackers to read arbitrary form definitions and submission records via a leaked bearer token granted they can load any page containing the Submissions Table block. NOTE: The developer released a patch for this issue in 3.13.1, but inadvertently introduced a REST API endpoint in which a valid bearer token could be minted for arbitrary form IDs, making this patch ineffective. CVE record
CVE-2025-10499, 27 Sep 2025
The Ninja Forms - The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.12.0. This is due to missing or incorrect nonce validation on the maybe_opt_in() function. This makes it possible for unauthenticated attackers to opt an affected site into usage statistics collection via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. CVE record
CVE-2025-10498, 27 Sep 2025
The Ninja Forms - The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.12.0. This is due to missing or incorrect nonce validation when exporting CSV files. This makes it possible for unauthenticated attackers to delete those files granted they can trick an administrator into performing an action such as clicking on a link. CVE record
CVE-2025-9083, 18 Sep 2025
The Ninja Forms WordPress plugin before 3.11.1 unserializes user input via form field, which could allow Unauthenticated users to perform PHP Object Injection when a suitable gadget is present on the blog. CVE record
CVE-2025-5398, 27 Jun 2025
The Ninja Forms - The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the use of a templating engine in all versions up to, and including, 3.10.2.1 due to insufficient output escaping on user data passed through the template. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2025-2524, 19 May 2025
The Ninja Forms WordPress plugin before 3.10.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). CVE record
CVE-2025-2560, 19 May 2025
The Ninja Forms WordPress plugin before 3.10.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). CVE record
CVE-2025-2561, 19 May 2025
The Ninja Forms WordPress plugin before 3.10.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). CVE record
CVE-2024-13470, 30 Jan 2025
The Ninja Forms - The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in all versions up to, and including, 3.8.24 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2024-12238, 29 Dec 2024
The The Ninja Forms - The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.8.22. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for authenticated attackers, with Subscriber-level access and above, to execute arbitrary shortcodes. CVE record
CVE-2024-11052, 12 Dec 2024
The Ninja Forms - The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the calculations parameter in all versions up to, and including, 3.8.19 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2024-3866, 25 Sep 2024
The Ninja Forms Contact Form plugin for WordPress is vulnerable to Reflected Self-Based Cross-Site Scripting via the 'Referer' header in all versions up to, and including, 3.8.15 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. Successful exploitation of this vulnerability requires "maintenance mode" for a targeted form to be enabled. However, there is no setting available to the attacker or even an administrator-level user to enable this mode. The mode is only enabled during a required update, which is a very short window of time. Additionally, because of the self-based nature of this vulnerability, attackers would have to rely on additional techniques to execute a supplied payload in the context of targeted user. CVE record
CVE-2024-7354, 2 Sep 2024
The Ninja Forms WordPress plugin before 3.8.11 does not escape an URL before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin CVE record
CVE-2024-2108, 29 Mar 2024
The Ninja Forms Contact Form - The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an image title embedded into a form in all versions up to, and including, 3.8.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2024-2113, 29 Mar 2024
The Ninja Forms Contact Form - The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.8.0. This is due to missing or incorrect nonce validation on the nf_download_all_subs AJAX action. This makes it possible for unauthenticated attackers to trigger an export of a form's submission to a publicly accessible location via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. CVE record
CVE-2024-0685, 2 Feb 2024
The Ninja Forms Contact Form - The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Second Order SQL Injection via the email address value submitted through forms in all versions up to, and including, 3.7.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to inject SQL in their email address that will append additional into the already existing query when an administrator triggers a personal data export. CVE record
CVE-2023-35909, 7 Dec 2023
Uncontrolled Resource Consumption vulnerability in Saturday Drive Ninja Forms Contact Form - The Drag and Drop Form Builder for WordPress leading to DoS.This issue affects Ninja Forms Contact Form - The Drag and Drop Form Builder for WordPress: from n/a through 3.6.25. CVE record
CVE-2023-5530, 6 Nov 2023
The Ninja Forms Contact Form WordPress plugin before 3.6.34 does not sanitize and escape its label fields, which could allow high privilege users such as admin to perform Stored XSS attacks. Only users with the unfiltered_html capability can perform this, and such users are already allowed to use JS in posts/comments etc however the vendor acknowledged and fixed the issue CVE record
CVE-2023-1835, 15 May 2023
The Ninja Forms Contact Form WordPress plugin before 3.6.22 does not properly escape user input before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin CVE record
CVE-2022-2903, 26 Sep 2022
The Ninja Forms Contact Form WordPress plugin before 3.6.13 unserialises the content of an imported file, which could lead to PHP object injections issues when an admin import (intentionally or not) a malicious file and a suitable gadget chain is present on the blog. CVE record
CVE-2021-25056, 4 Jul 2022
The Ninja Forms Contact Form WordPress plugin before 3.6.10 does not sanitise and escape field labels, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. CVE record
CVE-2021-25066, 4 Jul 2022
The Ninja Forms Contact Form WordPress plugin before 3.6.10 does not sanitize and escape some imported data, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. CVE record
CVE-2021-36827, 16 Jun 2022
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Saturday Drive's Ninja Forms Contact Form plugin <= 3.6.9 at WordPress via "label". CVE record
CVE-2021-24889, 29 Nov 2021
The Ninja Forms Contact Form WordPress plugin before 3.6.4 does not escape keys of the fields POST parameter, which could allow high privilege users to perform SQL injections attacks CVE record
CVE-2021-34647, 22 Sep 2021
The Ninja Forms WordPress plugin is vulnerable to sensitive information disclosure via the bulk_export_submissions function found in the ~/includes/Routes/Submissions.php file, in versions up to and including 3.5.7. This allows authenticated attackers to export all Ninja Forms submissions data via the /ninja-forms-submissions/export REST API which can include personally identifiable information. CVE record
CVE-2021-34648, 22 Sep 2021
The Ninja Forms WordPress plugin is vulnerable to arbitrary email sending via the trigger_email_action function found in the ~/includes/Routes/Submissions.php file, in versions up to and including 3.5.7. This allows authenticated attackers to send arbitrary emails from the affected server via the /ninja-forms-submissions/email-action REST API which can be used to socially engineer victims. CVE record
CVE-2021-24163, 5 Apr 2021
The AJAX action, wp_ajax_ninja_forms_sendwp_remote_install_handler, did not have a capability check on it, nor did it have any nonce protection, therefore making it possible for low-level users, such as subscribers, to install and activate the SendWP Ninja Forms Contact Form - The Drag and Drop Form Builder for WordPress WordPress plugin before 3.4.34 and retrieve the client_secret key needed to establish the SendWP connection while also installing the SendWP plugin. CVE record
CVE-2021-24164, 5 Apr 2021
In the Ninja Forms Contact Form WordPress plugin before 3.4.34.1, low-level users, such as subscribers, were able to trigger the action, wp_ajax_nf_oauth, and retrieve the connection url needed to establish a connection. They could also retrieve the client_id for an already established OAuth connection. CVE record
CVE-2021-24165, 5 Apr 2021
In the Ninja Forms Contact Form WordPress plugin before 3.4.34, the wp_ajax_nf_oauth_connect AJAX action was vulnerable to open redirect due to the use of a user supplied redirect parameter and no protection in place. CVE record
CVE-2021-24166, 5 Apr 2021
The wp_ajax_nf_oauth_disconnect from the Ninja Forms Contact Form - The Drag and Drop Form Builder for WordPress WordPress plugin before 3.4.34 had no nonce protection making it possible for attackers to craft a request to disconnect a site's OAuth connection. CVE record
CVE-2020-36173, 6 Jan 2021
The Ninja Forms plugin before 3.4.28 for WordPress lacks escaping for submissions-table fields. CVE record
CVE-2020-36174, 6 Jan 2021
The Ninja Forms plugin before 3.4.27.1 for WordPress allows CSRF via services integration. CVE record
CVE-2020-36175, 6 Jan 2021
The Ninja Forms plugin before 3.4.27.1 for WordPress allows attackers to bypass validation via the email field. CVE record
CVE-2020-12462, 29 Apr 2020
The ninja-forms plugin before 3.4.24.2 for WordPress allows CSRF with resultant XSS. CVE record
CVE-2020-8594, 14 Feb 2020
The Ninja Forms plugin 3.4.22 for WordPress has Multiple Stored XSS vulnerabilities via ninja_forms[recaptcha_site_key], ninja_forms[recaptcha_secret_key], ninja_forms[recaptcha_lang], or ninja_forms[date_format]. CVE record
CVE-2017-18574, 22 Aug 2019
The ninja-forms plugin before 3.0.31 for WordPress has insufficient HTML escaping in the builder. CVE record
CVE-2018-20980, 22 Aug 2019
The ninja-forms plugin before 3.2.15 for WordPress has parameter tampering. CVE record
CVE-2018-20981, 22 Aug 2019
The ninja-forms plugin before 3.3.9 for WordPress has insufficient restrictions on submission-data retrieval during Export Personal Data requests. CVE record
CVE-2019-15025, 14 Aug 2019
The ninja-forms plugin before 3.3.21.2 for WordPress has SQL injection in the search filter on the submissions page. CVE record
CVE-2019-10869, 7 May 2019
Path Traversal and Unrestricted File Upload exists in the Ninja Forms plugin before 3.0.23 for WordPress (when the Uploads add-on is activated). This allows an attacker to traverse the file system to access files and execute code via the includes/fields/upload.php (aka upload/submit page) name and tmp_name parameters. CVE record
CVE-2018-19796, 3 Dec 2018
An open redirect in the Ninja Forms plugin before 3.3.19.1 for WordPress allows Remote Attackers to redirect a user via the lib/StepProcessing/step-processing.php (aka submissions download page) redirect parameter. CVE record
CVE-2018-19287, 15 Nov 2018
XSS in the Ninja Forms plugin before 3.3.18 for WordPress allows Remote Attackers to execute JavaScript via the includes/Admin/Menus/Submissions.php (aka submissions page) begin_date, end_date, or form_id parameter. CVE record
CVE-2018-16308, 1 Sep 2018
The Ninja Forms plugin before 3.3.14.1 for WordPress allows CSV injection. CVE record
CVE-2018-7280, 21 Feb 2018
The Ninja Forms plugin before 3.2.14 for WordPress has XSS. CVE record
CVE-2016-1209, 14 May 2016
The Ninja Forms plugin before 2.9.42.1 for WordPress allows remote attackers to conduct PHP object injection attacks via crafted serialized values in a POST request. CVE record
CVE-2015-2220, 5 Mar 2015
Multiple cross-site scripting (XSS) vulnerabilities in the Ninja Forms plugin before 2.8.9 for WordPress allow (1) remote attackers to inject arbitrary web script or HTML via the ninja_forms_field_1 parameter in a ninja_forms_ajax_submit action to wp-admin/admin-ajax.php or (2) remote administrators to inject arbitrary web script or HTML via the fields[1] parameter to wp-admin/post.php. CVE record
CVE-2014-9688, 5 Mar 2015
Unspecified vulnerability in the Ninja Forms plugin before 2.8.10 for WordPress has unknown impact and remote attack vectors related to admin users. CVE record

What to do if you run Ninja Forms

If you run Ninja Forms, open WordPress and check the installed version in Plugins. Compare it with the affected versions in the vulnerability record. If a fixed version is available, take a current backup and update to that version or the latest supported release.

If no fixed version exists, consider disabling and removing the plugin or replacing it with a maintained alternative. After dealing with the affected software, check administrator users, unexpected file changes, redirects, unfamiliar pages and security logs for signs that the site may already have been altered.

Email me about new Ninja Forms vulnerabilities

Free. We email you when a new vulnerability is published for Ninja Forms, usually within minutes. Confirm by email; unsubscribe any time.

Focus on your business. We’ll take care of your website.

From everyday updates to ongoing care, we keep your website working.

Get website support