CVE · High

CVE-2026-1239 — Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.14.2

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-1239 Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.14.2 Missing Authorization High 7.5 < 3.14.2 3.14.2 2026-06-30

CVE-2026-1239

A vulnerability exists in the Ninja Forms plugin for WordPress, allowing unauthorized access to data due to a missing authentication check on a specific REST API endpoint. This allows attackers to view form submissions, potentially containing sensitive information, without needing to authenticate.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.