CVE · High

CVE-2025-11924 — Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.13.3

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-11924 Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.13.3 Authorization Bypass Through User-Controlled Key High 7.5 < 3.13.3 3.13.3 2025-12-16

CVE-2025-11924

The Ninja Forms plugin for WordPress has a security flaw that allows unauthorized access to sensitive data. In versions up to 3.13.2, the plugin doesn't properly check user permissions before sharing form information and submission records via its REST API. This allows attackers to view any form's data and submission history, even if they're not authenticated, by using a leaked access token.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.