Junglewise Threat Intelligence

CVE-2026-81772: Ninja Forms - Layout & Styles PHP Object Injection

CVE-2026-81772 · Severity: high · CVSS 8.8 · Published 2026-09-02

Vendors: Ninja Forms.

Executive brief

Ninja Forms - Layout & Styles is a popular WordPress plugin for customizing form layouts. An unauthenticated remote attacker can inject malicious PHP objects into the plugin, allowing them to execute arbitrary code on the web server with no authentication required. This could lead to full website compromise, data theft, or installation of malware.

Technical details

The vulnerability is a PHP Object Injection flaw in Ninja Forms - Layout & Styles version 3.0.31 and earlier. The plugin fails to properly validate user-supplied input before deserializing PHP objects, allowing an unauthenticated attacker to craft a malicious request that instantiates arbitrary classes and triggers dangerous functionality. The vulnerability requires no authentication and is network-reachable, making it easily exploitable at scale. An attacker can achieve remote code execution on the underlying server. The plugin was patched in version 3.0.32.

Affected products

  • Ninja Forms Layout & Styles <= 3.0.31

Timeline

  • 2026-09-02: disclosed: CVE published on NVD
  • 2026-09-02: patched: Fixed in version 3.0.32
  • 2026-03-10: other: Reported by Marc-André Beaulieu

References