CVE Database /
CVE-2025-11924
CVE · High
CVE-2025-11924 — Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.13.3
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2025-11924
|
Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.13.3 |
Authorization Bypass Through User-Controlled Key |
High
7.5
|
< 3.13.3
|
3.13.3 |
2025-12-16 |
—
|
CVE-2025-11924
The Ninja Forms plugin for WordPress has a security flaw that allows unauthorized access to sensitive data. In versions up to 3.13.2, the plugin doesn't properly check user permissions before sharing form information and submission records via its REST API. This allows attackers to view any form's data and submission history, even if they're not authenticated, by using a leaked access token.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings