HomeWordPress vulnerabilitiesNinja Forms
Ninja Forms vulnerabilities
Ninja Forms has 66 known vulnerabilities in this database. The most recent published record is dated 2 Oct 2026.
- Known vulnerabilities
- 66
- Active installs
- 600,000+
- Latest version
- 3.15.5
- Last updated
- 28 Sep 2026
- Most recent
- 2 Oct 2026
Find it in your WordPress dashboard under Plugins. Severity is based on the CVSS score published with the CVE where one is available.
| Vulnerability | Severity | Affected | Fix | Published |
|---|---|---|---|---|
| Cross-site scripting (XSS) CVE-2026-90438 | High 7.2 | Up to 3.15.4 | Fixed in a later version (latest 3.15.5) | 5 d ago |
| Remote code execution CVE-2026-91827 | High 7.5 | Not yet published | Check for an update | 22 Sep 2026 |
| Cross-site scripting (XSS) CVE-2026-92438 | High 8.8 | Not yet published | Check for an update | 22 Sep 2026 |
| Cross-site scripting (XSS) CVE-2026-94504 | High 7.2 | Not yet published | Check for an update | 22 Sep 2026 |
| PHP object injection CVE-2026-11363 | Medium 6.6 | Up to 3.14.6 | Fixed in a later version (latest 3.15.5) | 9 Sep 2026 |
| Security weakness CVE-2026-80437 | Medium 4.8 | Before 3.15.2 | Fixed in 3.15.2 | 6 Sep 2026 |
| Cross-site scripting (XSS) CVE-2026-19769 | High 7.2 | Up to 3.15.1 | Fixed in a later version (latest 3.15.5) | 5 Sep 2026 |
| Broken access control CVE-2026-80438 | Medium 5.9 | Before 3.15.2 | Fixed in 3.15.2 | 4 Sep 2026 |
| Security weakness CVE-2026-15256 | Medium 4.8 | Before 3.14.10 | Fixed in 3.14.10 | 6 Aug 2026 |
| SQL injection CVE-2026-15663 | Medium 4.9 | Up to 3.14.9 | Fixed in a later version (latest 3.15.5) | 24 Jul 2026 |
| Broken access control CVE-2026-65050 | Medium 6.5 | Not yet published | Check for an update | 21 Jul 2026 |
| Security weakness CVE-2026-65051 | Medium 6.5 | Not yet published | Check for an update | 21 Jul 2026 |
| Security weakness CVE-2026-65052 | High 7.5 | Not yet published | Check for an update | 21 Jul 2026 |
| Cross-site scripting (XSS) CVE-2026-65048 | Critical 9.3 | Up to 3.14.9 | Fixed in a later version (latest 3.15.5) | 21 Jul 2026 |
| Broken access control CVE-2026-65049 | Critical 9.3 | Not yet published | Check for an update | 21 Jul 2026 |
| Broken access control CVE-2026-1239 | High 7.5 | Up to 3.14.1 | Fixed in a later version (latest 3.15.5) | 1 Jul 2026 |
| Sensitive data exposure CVE-2026-1307 | Medium 6.5 | Up to 3.14.1 | Fixed in a later version (latest 3.15.5) | 28 Mar 2026 |
| Sensitive data exposure CVE-2026-2268 | High 7.5 | Up to 3.14.0 | Fixed in a later version (latest 3.15.5) | 10 Feb 2026 |
| Security weakness CVE-2025-14072 | Medium 5.3 | Before 3.13.3 | Fixed in 3.13.3 | 2 Jan 2026 |
| Broken access control CVE-2025-11924 | High 7.5 | Before 3.13.1 | Fixed in 3.13.1 | 17 Dec 2025 |
| Cross-site request forgery (CSRF) CVE-2025-10499 | Medium 4.3 | Before 3.12.1 | Fixed in 3.12.1 | 27 Sep 2025 |
| Cross-site request forgery (CSRF) CVE-2025-10498 | Medium 4.3 | Before 3.12.1 | Fixed in 3.12.1 | 27 Sep 2025 |
| PHP object injection CVE-2025-9083 | Critical 9.8 | Before 3.11.1 | Fixed in 3.11.1 | 18 Sep 2025 |
| Cross-site scripting (XSS) CVE-2025-5398 | Medium 6.4 | Before 3.10.2.2 | Fixed in 3.10.2.2 | 27 Jun 2025 |
| Cross-site scripting (XSS) CVE-2025-2524 | Medium 4.8 | Before 3.10.1 | Fixed in 3.10.1 | 19 May 2025 |
| Cross-site scripting (XSS) CVE-2025-2560 | Medium 4.8 | Before 3.10.1 | Fixed in 3.10.1 | 19 May 2025 |
| Cross-site scripting (XSS) CVE-2025-2561 | Medium 4.8 | Before 3.10.1 | Fixed in 3.10.1 | 19 May 2025 |
| Cross-site scripting (XSS) CVE-2024-13470 | Medium 6.4 | Before 3.8.25 | Fixed in 3.8.25 | 30 Jan 2025 |
| Remote code execution CVE-2024-12238 | Medium 6.3 | Before 3.8.23 | Fixed in 3.8.23 | 29 Dec 2024 |
| Cross-site scripting (XSS) CVE-2024-11052 | High 7.2 | Before 3.8.20 | Fixed in 3.8.20 | 12 Dec 2024 |
| Cross-site scripting (XSS) CVE-2024-3866 | Medium 4.7 | Before 3.8.16 | Fixed in 3.8.16 | 25 Sep 2024 |
| Cross-site scripting (XSS) CVE-2024-7354 | Medium 6.1 | Before 3.8.11 | Fixed in 3.8.11 | 2 Sep 2024 |
| Cross-site scripting (XSS) CVE-2024-2108 | Medium 4.6 | Before 3.8.1 | Fixed in 3.8.1 | 29 Mar 2024 |
| Cross-site request forgery (CSRF) CVE-2024-2113 | Medium 4.3 | Before 3.8.1 | Fixed in 3.8.1 | 29 Mar 2024 |
| SQL injection CVE-2024-0685 | Medium 5.9 | Up to 3.7.1 | Fixed in a later version (latest 3.15.5) | 2 Feb 2024 |
| Denial of service CVE-2023-35909 | Medium 5.3 | Before 3.6.26 | Fixed in 3.6.26 | 7 Dec 2023 |
| Cross-site scripting (XSS) CVE-2023-5530 | Medium 4.8 | Before 3.6.34 | Fixed in 3.6.34 | 6 Nov 2023 |
| Cross-site scripting (XSS) CVE-2023-1835 | Medium 6.1 | Before 3.6.22 | Fixed in 3.6.22 | 15 May 2023 |
| PHP object injection CVE-2022-2903 | High 7.2 | Before 3.6.13 | Fixed in 3.6.13 | 26 Sep 2022 |
| Cross-site scripting (XSS) CVE-2021-25056 | Medium 4.8 | Before 3.6.10 | Fixed in 3.6.10 | 4 Jul 2022 |
| Cross-site scripting (XSS) CVE-2021-25066 | Medium 4.8 | Before 3.6.10 | Fixed in 3.6.10 | 4 Jul 2022 |
| Cross-site scripting (XSS) CVE-2021-36827 | Medium 4.8 | Up to 3.6.9 | Fixed in a later version (latest 3.15.5) | 16 Jun 2022 |
| SQL injection CVE-2021-24889 | High 7.2 | Before 3.6.4 | Fixed in 3.6.4 | 29 Nov 2021 |
| Sensitive data exposure CVE-2021-34647 | Medium 6.5 | Up to 3.5.7 | Fixed in a later version (latest 3.15.5) | 22 Sep 2021 |
| Broken access control CVE-2021-34648 | Medium 6.4 | Up to 3.5.7 | Fixed in a later version (latest 3.15.5) | 22 Sep 2021 |
| Sensitive data exposure CVE-2021-24163 | High 8.8 | Before 3.4.34 | Fixed in 3.4.34 | 5 Apr 2021 |
| Sensitive data exposure CVE-2021-24164 | Medium 4.3 | Before 3.4.34.1 | Fixed in 3.4.34.1 | 5 Apr 2021 |
| Open redirect CVE-2021-24165 | Medium 6.1 | Before 3.4.34 | Fixed in 3.4.34 | 5 Apr 2021 |
| Cross-site request forgery (CSRF) CVE-2021-24166 | Medium 5.4 | Before 3.4.34 | Fixed in 3.4.34 | 5 Apr 2021 |
| Security weakness CVE-2020-36173 | Medium 5.3 | Before 3.4.28 | Fixed in 3.4.28 | 6 Jan 2021 |
| Cross-site request forgery (CSRF) CVE-2020-36174 | Medium 6.5 | Before 3.4.27.1 | Fixed in 3.4.27.1 | 6 Jan 2021 |
| Security weakness CVE-2020-36175 | Medium 5.3 | Before 3.4.27.1 | Fixed in 3.4.27.1 | 6 Jan 2021 |
| Cross-site scripting (XSS) CVE-2020-12462 | Medium 6.1 | Before 3.4.24.2 | Fixed in 3.4.24.2 | 29 Apr 2020 |
| Cross-site scripting (XSS) CVE-2020-8594 | Medium 5.4 | Not yet published | Check for an update | 14 Feb 2020 |
| Security weakness CVE-2017-18574 | Medium 6.1 | Before 3.0.31 | Fixed in 3.0.31 | 22 Aug 2019 |
| Security weakness CVE-2018-20980 | High 7.5 | Before 3.2.15 | Fixed in 3.2.15 | 22 Aug 2019 |
| Security weakness CVE-2018-20981 | Critical 9.1 | Before 3.3.9 | Fixed in 3.3.9 | 22 Aug 2019 |
| SQL injection CVE-2019-15025 | Critical 9.8 | Before 3.3.21.2 | Fixed in 3.3.21.2 | 14 Aug 2019 |
| Arbitrary file upload CVE-2019-10869 | High 8.1 | Before 3.0.23 | Fixed in 3.0.23 | 7 May 2019 |
| Open redirect CVE-2018-19796 | Medium 6.1 | Before 3.3.19.1 | Fixed in 3.3.19.1 | 3 Dec 2018 |
| Cross-site scripting (XSS) CVE-2018-19287 | Medium 6.1 | Before 3.3.18 | Fixed in 3.3.18 | 15 Nov 2018 |
| CSV injection CVE-2018-16308 | High 8.6 | Before 3.3.14.1 | Fixed in 3.3.14.1 | 1 Sep 2018 |
| Cross-site scripting (XSS) CVE-2018-7280 | Medium 6.1 | Before 3.2.14 | Fixed in 3.2.14 | 21 Feb 2018 |
| PHP object injection CVE-2016-1209 | Critical 9.8 | Up to 2.9.42 | Fixed in a later version (latest 3.15.5) | 14 May 2016 |
| Cross-site scripting (XSS) CVE-2015-2220 | Not scored | Up to 2.8.8 | Fixed in a later version (latest 3.15.5) | 5 Mar 2015 |
| Security weakness CVE-2014-9688 | Not scored | Up to 2.8.9 | Fixed in a later version (latest 3.15.5) | 5 Mar 2015 |
Read the published descriptions
- CVE-2026-90438, 2 Oct 2026
- The Ninja Forms - The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Paragraph Text (RTE) Field Submission in all versions up to, and including, 3.15.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is only exploitable when the targeted Paragraph Text field has the Rich Text Editor (RTE) option enabled. CVE record
- CVE-2026-91827, 22 Sep 2026
- The Ninja Forms WordPress plugin 3.15.3 does not prevent user-submitted form field values from being deserialised when an administrator later exports form submissions to CSV, allowing unauthenticated attackers to perform PHP Object Injection; if a suitable POP chain is present via another installed plugin or theme, this can lead to actions such as arbitrary file operations or remote code execution. CVE record
- CVE-2026-92438, 22 Sep 2026
- The Ninja Forms WordPress plugin 3.15.3 does not escape submitted form field values before outputting them on the submission edit screen in the admin area, which could allow unauthenticated users to submit values through a public form that then execute in the browser of any high-privileged user who reviews the submission. CVE record
- CVE-2026-94504, 22 Sep 2026
- Ninja Forms 3.15.3 stores an anonymous non-RTE textarea value and renders it without safe HTML encoding in the legacy submission editor. An attacker can break out of the textarea with stored script. When an Administrator opens the attacker-known direct submission URL, the script runs in the WordPress admin origin. CVE record
- CVE-2026-11363, 9 Sep 2026
- The Ninja Forms - The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.14.6 via deserialization of untrusted input . This makes it possible for authenticated attackers, with administrator-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target system, it may allow the attacker to perform actions like delete arbitrary files, retrieve sensitive data, or execute code depending on the POP chain present. The deserialization is triggered automatically during form import when WPN_Helper::build_nf_cache() invokes $action->get_settings() immediately after the crafted form is imported, requiring no further interaction beyond the import action itself. CVE record
- CVE-2026-80437, 6 Sep 2026
- The Ninja Forms WordPress plugin from 3.14.10 before 3.15.2 does not prevent shortcodes in request-derived values from being executed when it substitutes them into content it later processes for shortcodes, allowing unauthenticated users to run any shortcode registered on the site. CVE record
- CVE-2026-19769, 5 Sep 2026
- The Ninja Forms - The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Repeater Child 'type' Confusion via Unmatched Array Key in all versions up to, and including, 3.15.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires the Ninja Forms File Uploads add-on to be active, as the attack routes the unwhitelisted child entry through the File Uploads handler to write an attacker-supplied HTML file containing arbitrary JavaScript into any web-server-writable directory, including the site root, where it is served from the site's own origin. CVE record
- CVE-2026-80438, 4 Sep 2026
- The Ninja Forms WordPress plugin before 3.15.2 does not restrict its REST abilities to administrators, accepting a Ninja Forms WordPress plugin before 3.15.2-specific capability as equivalent to full site administration, which allows any user granted that capability to read Ninja Forms WordPress plugin before 3.15.2 settings and stored form submissions, overwrite the Ninja Forms WordPress plugin before 3.15.2's configuration, and create or modify arbitrary posts and pages. The capability belongs to no default WordPress role and the Ninja Forms WordPress plugin before 3.15.2 never grants it, so an administrator must have assigned it, typically when delegating access to the form builder. CVE record
- CVE-2026-15256, 6 Aug 2026
- The Ninja Forms WordPress plugin before 3.14.10 does not prevent user-supplied query-string input, used to pre-populate a form field's default value, from being processed as a shortcode, allowing unauthenticated attackers to execute arbitrary shortcodes registered on the site when a form so configured is embedded on a public page. CVE record
- CVE-2026-15663, 24 Jul 2026
- The Ninja Forms - The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to generic SQL Injection via Import File 'settings' Key in all versions up to, and including, 3.14.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. The vulnerable keys originate from the 'settings' object in an attacker-controlled import file processed via file_get_contents() or base64-decoded/JSON-decoded blobs, bypassing wp_magic_quotes protections entirely; two distinct sinks are affected - _save_setting() in Model.php and insert_form_meta() in ImportForm.php - as only the value side is escaped while the key side receives no sanitization or parameterization at any point in the call chain. CVE record
- CVE-2026-65050, 21 Jul 2026
- Ninja Forms WordPress plugin version 3.14.8 and prior contains a missing authorization vulnerability in the render callback of the `ninja-forms/submissions-table` Gutenberg block that allows authenticated attackers with Author-level privileges to expose stored form submissions to unauthenticated visitors by embedding the block with an arbitrary formID on a published post. Attackers can retrieve the signed bearer token injected into every page visitor's browser via `wp_localize_script` and use it against the REST API submissions endpoint to access all saved form submission field values, including sensitive personally identifiable information such as names, email addresses, and phone numbers. CVE record
- CVE-2026-65051, 21 Jul 2026
- Ninja Forms WordPress plugin version 3.14.8 contains a client-side enforcement of server-side security vulnerability that allows unauthenticated attackers to bypass all form validation by merging attacker-controlled field metadata over server-loaded form definitions before validation runs. Attackers can craft a malicious AJAX submission overriding field types, removing required flags, and disabling CAPTCHA checks through the nopriv AJAX endpoint to trigger form actions such as email notifications and database storage with unverified, attacker-controlled content. CVE record
- CVE-2026-65052, 21 Jul 2026
- Ninja Forms WordPress plugin version 3.14.8 and prior contains an improper input validation vulnerability that allows unauthenticated attackers to inject arbitrary numeric values into form calculations and payment totals by submitting values that do not match any configured option in ListSelect or ListRadio fields. Attackers can tamper with form submission payloads to the ajax submit endpoint, causing the get_calc_value() method to fail open and return attacker-controlled values, enabling manipulation of payment amounts to zero or arbitrary figures and bypassing admin-configured pricing logic. CVE record
- CVE-2026-65048, 21 Jul 2026
- Ninja Forms plugin for WordPress versions 3.10.4 through 3.14.9 contains an unauthenticated stored cross-site scripting vulnerability in the Repeatable Fieldset feature where parseSubmissionIndex() accepts arbitrary strings as submission indexes without numeric validation, and admin_form_element() interpolates the index directly into HTML without escaping. An unauthenticated attacker can submit a public form with a crafted repeater child key containing malicious script payloads, which execute in an administrator's browser when viewing submissions in the WordPress admin panel, enabling session-cookie theft, creation of administrator accounts, installation of malicious plugins, and arbitrary modification of site content. CVE record
- CVE-2026-65049, 21 Jul 2026
- Ninja Forms plugin version 3.14.8 and prior for WordPress Multisite contains an incorrect authorization vulnerability that allows a subsite Administrator to trigger network-wide deletion of all Ninja Forms data by exploiting a site-scoped capability check combined with unsafe multisite migration defaults. Attackers can send a crafted POST request to the admin-ajax.php endpoint with the nf_delete_all_data action and a per-site nonce to invoke migration routines that unconditionally iterate all blogs via switch_to_blog(), dropping all nf3_* tables and clearing options and transients across every subsite in the network without requiring super-admin or network-admin privileges. CVE record
- CVE-2026-1239, 1 Jul 2026
- The Ninja Forms - The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to unauthorized access of data due to a missing authorization check on the 'ninja-forms-views/token/refresh' REST callback in all versions up to, and including, 3.14.1. This makes it possible for unauthenticated attackers to view form submissions, which could potentially contain sensitive information. CVE record
- CVE-2026-1307, 28 Mar 2026
- The Ninja Forms - The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.14.1 via a callback function for the admin_enqueue_scripts action handler in blocks/bootstrap.php. This makes it possible for authenticated attackers, with Contributor-level access and above, to gain access to an authorization token to view form submissions for arbitrary forms, which could potentially contain sensitive information. CVE record
- CVE-2026-2268, 10 Feb 2026
- The Ninja Forms plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.14.0. This is due to the unsafe application of the `ninja_forms_merge_tags` filter to user-supplied input within repeater fields, which allows the resolution of `{post_meta:KEY}` merge tags without authorization checks. This makes it possible for unauthenticated attackers to extract arbitrary post metadata from any post on the site, including sensitive data such as WooCommerce billing emails, API keys, private tokens, and customer personal information via the `nf_ajax_submit` AJAX action. CVE record
- CVE-2025-14072, 2 Jan 2026
- The Ninja Forms WordPress plugin before 3.13.3 allows unauthenticated attackers to generate valid access tokens via the REST API which can then be used to read form submissions. CVE record
- CVE-2025-11924, 17 Dec 2025
- The Ninja Forms - The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.13.2. This is due to the plugin not properly verifying that a user is authorized before the `ninja-forms-views` REST endpoints return form metadata and submission content. This makes it possible for unauthenticated attackers to read arbitrary form definitions and submission records via a leaked bearer token granted they can load any page containing the Submissions Table block. NOTE: The developer released a patch for this issue in 3.13.1, but inadvertently introduced a REST API endpoint in which a valid bearer token could be minted for arbitrary form IDs, making this patch ineffective. CVE record
- CVE-2025-10499, 27 Sep 2025
- The Ninja Forms - The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.12.0. This is due to missing or incorrect nonce validation on the maybe_opt_in() function. This makes it possible for unauthenticated attackers to opt an affected site into usage statistics collection via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. CVE record
- CVE-2025-10498, 27 Sep 2025
- The Ninja Forms - The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.12.0. This is due to missing or incorrect nonce validation when exporting CSV files. This makes it possible for unauthenticated attackers to delete those files granted they can trick an administrator into performing an action such as clicking on a link. CVE record
- CVE-2025-9083, 18 Sep 2025
- The Ninja Forms WordPress plugin before 3.11.1 unserializes user input via form field, which could allow Unauthenticated users to perform PHP Object Injection when a suitable gadget is present on the blog. CVE record
- CVE-2025-5398, 27 Jun 2025
- The Ninja Forms - The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the use of a templating engine in all versions up to, and including, 3.10.2.1 due to insufficient output escaping on user data passed through the template. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
- CVE-2025-2524, 19 May 2025
- The Ninja Forms WordPress plugin before 3.10.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). CVE record
- CVE-2025-2560, 19 May 2025
- The Ninja Forms WordPress plugin before 3.10.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). CVE record
- CVE-2025-2561, 19 May 2025
- The Ninja Forms WordPress plugin before 3.10.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). CVE record
- CVE-2024-13470, 30 Jan 2025
- The Ninja Forms - The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in all versions up to, and including, 3.8.24 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
- CVE-2024-12238, 29 Dec 2024
- The The Ninja Forms - The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.8.22. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for authenticated attackers, with Subscriber-level access and above, to execute arbitrary shortcodes. CVE record
- CVE-2024-11052, 12 Dec 2024
- The Ninja Forms - The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the calculations parameter in all versions up to, and including, 3.8.19 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
- CVE-2024-3866, 25 Sep 2024
- The Ninja Forms Contact Form plugin for WordPress is vulnerable to Reflected Self-Based Cross-Site Scripting via the 'Referer' header in all versions up to, and including, 3.8.15 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. Successful exploitation of this vulnerability requires "maintenance mode" for a targeted form to be enabled. However, there is no setting available to the attacker or even an administrator-level user to enable this mode. The mode is only enabled during a required update, which is a very short window of time. Additionally, because of the self-based nature of this vulnerability, attackers would have to rely on additional techniques to execute a supplied payload in the context of targeted user. CVE record
- CVE-2024-7354, 2 Sep 2024
- The Ninja Forms WordPress plugin before 3.8.11 does not escape an URL before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin CVE record
- CVE-2024-2108, 29 Mar 2024
- The Ninja Forms Contact Form - The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an image title embedded into a form in all versions up to, and including, 3.8.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
- CVE-2024-2113, 29 Mar 2024
- The Ninja Forms Contact Form - The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.8.0. This is due to missing or incorrect nonce validation on the nf_download_all_subs AJAX action. This makes it possible for unauthenticated attackers to trigger an export of a form's submission to a publicly accessible location via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. CVE record
- CVE-2024-0685, 2 Feb 2024
- The Ninja Forms Contact Form - The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Second Order SQL Injection via the email address value submitted through forms in all versions up to, and including, 3.7.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to inject SQL in their email address that will append additional into the already existing query when an administrator triggers a personal data export. CVE record
- CVE-2023-35909, 7 Dec 2023
- Uncontrolled Resource Consumption vulnerability in Saturday Drive Ninja Forms Contact Form - The Drag and Drop Form Builder for WordPress leading to DoS.This issue affects Ninja Forms Contact Form - The Drag and Drop Form Builder for WordPress: from n/a through 3.6.25. CVE record
- CVE-2023-5530, 6 Nov 2023
- The Ninja Forms Contact Form WordPress plugin before 3.6.34 does not sanitize and escape its label fields, which could allow high privilege users such as admin to perform Stored XSS attacks. Only users with the unfiltered_html capability can perform this, and such users are already allowed to use JS in posts/comments etc however the vendor acknowledged and fixed the issue CVE record
- CVE-2023-1835, 15 May 2023
- The Ninja Forms Contact Form WordPress plugin before 3.6.22 does not properly escape user input before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin CVE record
- CVE-2022-2903, 26 Sep 2022
- The Ninja Forms Contact Form WordPress plugin before 3.6.13 unserialises the content of an imported file, which could lead to PHP object injections issues when an admin import (intentionally or not) a malicious file and a suitable gadget chain is present on the blog. CVE record
- CVE-2021-25056, 4 Jul 2022
- The Ninja Forms Contact Form WordPress plugin before 3.6.10 does not sanitise and escape field labels, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. CVE record
- CVE-2021-25066, 4 Jul 2022
- The Ninja Forms Contact Form WordPress plugin before 3.6.10 does not sanitize and escape some imported data, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. CVE record
- CVE-2021-36827, 16 Jun 2022
- Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Saturday Drive's Ninja Forms Contact Form plugin <= 3.6.9 at WordPress via "label". CVE record
- CVE-2021-24889, 29 Nov 2021
- The Ninja Forms Contact Form WordPress plugin before 3.6.4 does not escape keys of the fields POST parameter, which could allow high privilege users to perform SQL injections attacks CVE record
- CVE-2021-34647, 22 Sep 2021
- The Ninja Forms WordPress plugin is vulnerable to sensitive information disclosure via the bulk_export_submissions function found in the ~/includes/Routes/Submissions.php file, in versions up to and including 3.5.7. This allows authenticated attackers to export all Ninja Forms submissions data via the /ninja-forms-submissions/export REST API which can include personally identifiable information. CVE record
- CVE-2021-34648, 22 Sep 2021
- The Ninja Forms WordPress plugin is vulnerable to arbitrary email sending via the trigger_email_action function found in the ~/includes/Routes/Submissions.php file, in versions up to and including 3.5.7. This allows authenticated attackers to send arbitrary emails from the affected server via the /ninja-forms-submissions/email-action REST API which can be used to socially engineer victims. CVE record
- CVE-2021-24163, 5 Apr 2021
- The AJAX action, wp_ajax_ninja_forms_sendwp_remote_install_handler, did not have a capability check on it, nor did it have any nonce protection, therefore making it possible for low-level users, such as subscribers, to install and activate the SendWP Ninja Forms Contact Form - The Drag and Drop Form Builder for WordPress WordPress plugin before 3.4.34 and retrieve the client_secret key needed to establish the SendWP connection while also installing the SendWP plugin. CVE record
- CVE-2021-24164, 5 Apr 2021
- In the Ninja Forms Contact Form WordPress plugin before 3.4.34.1, low-level users, such as subscribers, were able to trigger the action, wp_ajax_nf_oauth, and retrieve the connection url needed to establish a connection. They could also retrieve the client_id for an already established OAuth connection. CVE record
- CVE-2021-24165, 5 Apr 2021
- In the Ninja Forms Contact Form WordPress plugin before 3.4.34, the wp_ajax_nf_oauth_connect AJAX action was vulnerable to open redirect due to the use of a user supplied redirect parameter and no protection in place. CVE record
- CVE-2021-24166, 5 Apr 2021
- The wp_ajax_nf_oauth_disconnect from the Ninja Forms Contact Form - The Drag and Drop Form Builder for WordPress WordPress plugin before 3.4.34 had no nonce protection making it possible for attackers to craft a request to disconnect a site's OAuth connection. CVE record
- CVE-2020-36173, 6 Jan 2021
- The Ninja Forms plugin before 3.4.28 for WordPress lacks escaping for submissions-table fields. CVE record
- CVE-2020-36174, 6 Jan 2021
- The Ninja Forms plugin before 3.4.27.1 for WordPress allows CSRF via services integration. CVE record
- CVE-2020-36175, 6 Jan 2021
- The Ninja Forms plugin before 3.4.27.1 for WordPress allows attackers to bypass validation via the email field. CVE record
- CVE-2020-12462, 29 Apr 2020
- The ninja-forms plugin before 3.4.24.2 for WordPress allows CSRF with resultant XSS. CVE record
- CVE-2020-8594, 14 Feb 2020
- The Ninja Forms plugin 3.4.22 for WordPress has Multiple Stored XSS vulnerabilities via ninja_forms[recaptcha_site_key], ninja_forms[recaptcha_secret_key], ninja_forms[recaptcha_lang], or ninja_forms[date_format]. CVE record
- CVE-2017-18574, 22 Aug 2019
- The ninja-forms plugin before 3.0.31 for WordPress has insufficient HTML escaping in the builder. CVE record
- CVE-2018-20980, 22 Aug 2019
- The ninja-forms plugin before 3.2.15 for WordPress has parameter tampering. CVE record
- CVE-2018-20981, 22 Aug 2019
- The ninja-forms plugin before 3.3.9 for WordPress has insufficient restrictions on submission-data retrieval during Export Personal Data requests. CVE record
- CVE-2019-15025, 14 Aug 2019
- The ninja-forms plugin before 3.3.21.2 for WordPress has SQL injection in the search filter on the submissions page. CVE record
- CVE-2019-10869, 7 May 2019
- Path Traversal and Unrestricted File Upload exists in the Ninja Forms plugin before 3.0.23 for WordPress (when the Uploads add-on is activated). This allows an attacker to traverse the file system to access files and execute code via the includes/fields/upload.php (aka upload/submit page) name and tmp_name parameters. CVE record
- CVE-2018-19796, 3 Dec 2018
- An open redirect in the Ninja Forms plugin before 3.3.19.1 for WordPress allows Remote Attackers to redirect a user via the lib/StepProcessing/step-processing.php (aka submissions download page) redirect parameter. CVE record
- CVE-2018-19287, 15 Nov 2018
- XSS in the Ninja Forms plugin before 3.3.18 for WordPress allows Remote Attackers to execute JavaScript via the includes/Admin/Menus/Submissions.php (aka submissions page) begin_date, end_date, or form_id parameter. CVE record
- CVE-2018-16308, 1 Sep 2018
- The Ninja Forms plugin before 3.3.14.1 for WordPress allows CSV injection. CVE record
- CVE-2018-7280, 21 Feb 2018
- The Ninja Forms plugin before 3.2.14 for WordPress has XSS. CVE record
- CVE-2016-1209, 14 May 2016
- The Ninja Forms plugin before 2.9.42.1 for WordPress allows remote attackers to conduct PHP object injection attacks via crafted serialized values in a POST request. CVE record
- CVE-2015-2220, 5 Mar 2015
- Multiple cross-site scripting (XSS) vulnerabilities in the Ninja Forms plugin before 2.8.9 for WordPress allow (1) remote attackers to inject arbitrary web script or HTML via the ninja_forms_field_1 parameter in a ninja_forms_ajax_submit action to wp-admin/admin-ajax.php or (2) remote administrators to inject arbitrary web script or HTML via the fields[1] parameter to wp-admin/post.php. CVE record
- CVE-2014-9688, 5 Mar 2015
- Unspecified vulnerability in the Ninja Forms plugin before 2.8.10 for WordPress has unknown impact and remote attack vectors related to admin users. CVE record
What to do if you run Ninja Forms
If you run Ninja Forms, open WordPress and check the installed version in Plugins. Compare it with the affected versions in the vulnerability record. If a fixed version is available, take a current backup and update to that version or the latest supported release.
If no fixed version exists, consider disabling and removing the plugin or replacing it with a maintained alternative. After dealing with the affected software, check administrator users, unexpected file changes, redirects, unfamiliar pages and security logs for signs that the site may already have been altered.
Email me about new Ninja Forms vulnerabilities
Free. We email you when a new vulnerability is published for Ninja Forms, usually within minutes. Confirm by email; unsubscribe any time.
Focus on your business. We’ll take care of your website.
From everyday updates to ongoing care, we keep your website working.