Executive brief
The Ninja Forms - Excel Export plugin for WordPress, which allows site administrators to export form submissions to spreadsheets, contains a security flaw. An attacker with basic user access (such as a subscriber) can exploit this to save spreadsheet files to unauthorized locations on the web server. This could be used as a stepping stone for more complex attacks against the website's infrastructure.
Technical details
A directory traversal vulnerability exists in the Ninja Forms - Excel Export plugin for WordPress due to insufficient validation of the 'spreadsheet_export_tmp_name' parameter. The flaw is located within the file handling logic, specifically affecting components like ExtractPostData.php and ExportFile.php. An authenticated attacker with at least subscriber-level privileges can manipulate this parameter to perform path traversal, allowing them to write .xls or .xlsx files to arbitrary directories on the server. While the impact is limited to file creation (integrity), it can be leveraged to stage further attacks or disrupt server organization. The vulnerability affects all versions up to and including 3.3.6.
Affected products
- SaturdayDrive Ninja Forms - Excel Export up to, and including, 3.3.6
Timeline
- 2026-07-17: advisory: NVD published the CVE record based on Wordfence data.
References
- https://plugins.trac.wordpress.org/browser/ninja-forms-excel-export/trunk/includes/Admin/ExtractPostData.php
- https://plugins.trac.wordpress.org/browser/ninja-forms-excel-export/trunk/includes/Handlers/ExportFile.php
- https://plugins.trac.wordpress.org/browser/ninja-forms-excel-export/trunk/ninja-forms-excel-export.php
- https://www.wordfence.com/threat-intel/vulnerabilities/id/24fb24cc-c29f-4d2d-87ba-5d211386e7dd?source=cve