CVE · High

CVE-2023-38386 — Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.6.26

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-38386 Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.6.26 Missing Authorization High 7.6 < 3.6.26 3.6.26 2023-07-25

CVE-2023-38386

A vulnerability exists in Ninja Forms plugin for WordPress, allowing authenticated users with contributor-level access or higher to access sensitive data without proper authorization. This is due to a missing capability check in the export_listen() function, which can be exploited through a specially crafted request. As a result, attackers can potentially obtain unauthorized access to form submissions.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.