Executive brief
Ninja Forms - Layout & Styles is a popular WordPress plugin for customizing form layouts. An unauthenticated remote attacker can inject malicious PHP objects into the plugin, allowing them to execute arbitrary code on the web server with no authentication required. This could lead to full website compromise, data theft, or installation of malware.
Technical details
The vulnerability is a PHP Object Injection flaw in Ninja Forms - Layout & Styles version 3.0.31 and earlier. The plugin fails to properly validate user-supplied input before deserializing PHP objects, allowing an unauthenticated attacker to craft a malicious request that instantiates arbitrary classes and triggers dangerous functionality. The vulnerability requires no authentication and is network-reachable, making it easily exploitable at scale. An attacker can achieve remote code execution on the underlying server. The plugin was patched in version 3.0.32.
Affected products
- Ninja Forms Layout & Styles <= 3.0.31
Timeline
- 2026-09-02: disclosed: CVE published on NVD
- 2026-09-02: patched: Fixed in version 3.0.32
- 2026-03-10: other: Reported by Marc-André Beaulieu