Junglewise Threat Intelligence

CVE-2026-65050: Saturday Drive Ninja Forms missing authorization in submissions-table block

CVE-2026-65050 · Severity: medium · CVSS 6.5 · Published 2026-07-21

Technologies: Saturday Drive Ninja Forms. Vendors: Saturday Drive.

Executive brief

Ninja Forms, a popular WordPress plugin used for creating contact and data collection forms, contains a security flaw that could allow unauthorized access to sensitive information. An attacker with basic 'Author' permissions on a website can manipulate a specific page element to expose private form submissions to the public. This could lead to the theft of personal data such as names, email addresses, and phone numbers submitted by other users.

Technical details

A missing authorization vulnerability exists in the render callback of the 'ninja-forms/submissions-table' Gutenberg block in Ninja Forms versions 3.14.8 and prior. Authenticated attackers with Author-level privileges can exploit this by embedding the block with an arbitrary formID on a published post. This action causes a signed bearer token to be injected into the browsers of all page visitors via 'wp_localize_script'. An attacker can then retrieve this token and use it against the REST API submissions endpoint to access all saved form submission field values, including PII. The issue is resolved in version 3.14.9.

Affected products

  • Saturday Drive Ninja Forms <= 3.14.8

Timeline

  • 2026-07-21: advisory
  • 2026-07-21: disclosed
  • 3.14.9: patched

References

Related threats