Junglewise Threat Intelligence

CVE-2026-42741: Aman Ninja Forms Views blind SQL injection

CVE-2026-42741 · Severity: high · CVSS 8.5 · Published 2026-05-12

Executive brief

A security vulnerability exists in a WordPress plugin used to display and edit form submissions on website frontends. An attacker with basic user permissions could potentially access or extract sensitive information from the website's database. This could lead to the exposure of private user data or form submission details, impacting the confidentiality of the site's information.

Technical details

The 'Ninja Forms Views – Display & Edit Ninja Forms Submissions on your site frontend' plugin (views-for-ninja-forms) for WordPress is vulnerable to Blind SQL Injection due to improper neutralization of special elements in SQL commands. The vulnerability exists in versions up to and including 3.3.2. An attacker with low-level authentication (PR:L) can exploit this over the network without user interaction to perform unauthorized database queries. According to the CVSS vector, this can result in high confidentiality impact and low availability impact. Users are advised to update to a version newer than 3.3.2 if available.

Affected products

  • Aman Ninja Forms Views – Display & Edit Ninja Forms Submissions on your site frontend n/a through 3.3.2

Timeline

  • 2026-05-12: disclosed
  • 2026-05-12: advisory

References