Executive brief
Ninja Forms is a popular WordPress form-building plugin. A flaw in its REST API access controls allows users with a specific form-builder capability to bypass authentication and perform actions restricted to administrators, including reading sensitive form data, modifying site content, and stealing CAPTCHA credentials. An admin must have explicitly granted this capability to trigger exploitation, but once granted, it creates a persistent security gap.
Technical details
The vulnerability is a broken access control flaw (CWE-284) in Ninja Forms' REST API endpoints. The plugin treats a plugin-specific capability (`nf_edit_forms`) as equivalent to full site administration, without properly restricting endpoint access to actual WordPress administrators. An authenticated user holding this capability can invoke REST endpoints to read plugin settings, export form submissions, access draft/private content, and modify any published post. The attack requires the user to be logged in and possess a valid REST nonce, but no additional privilege. The flaw was fixed in version 3.15.2; all versions from 3.14.0 to 3.15.1 are affected.
Affected products
- Ninja Forms Ninja Forms 3.14.0 to 3.15.1
Timeline
- 2026-09-02: disclosed
- 2026-09-04: patched: Fixed in version 3.15.2