CVE · High

CVE-2023-38393 — Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.6.26

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-38393 Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.6.26 Missing Authorization High 7.6 < 3.6.26 3.6.26 2023-07-25

CVE-2023-38393

A vulnerability exists in Ninja Forms plugin for WordPress, specifically in versions up to and including 3.6.25, where an authenticated attacker with subscriber-level access or higher can access sensitive data without proper authorization. This is due to a missing capability check in the processing function, allowing the attacker to exploit the nf_download_all_subs AJAX action to export form submissions.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.