CVE-2026-65049
The Ninja Forms plugin for WordPress Multisite versions prior to 3.14.8 contains a security flaw that allows a subsite administrator to delete all Ninja Forms data across the entire network. This is possible because the plugin's authorization checks are flawed, allowing an attacker to send a specially crafted request to the admin-ajax.php endpoint, which then triggers a migration routine that deletes data from all subsites in the network. The deletion process is not restricted to super-admin or network-admin privileges, making it vulnerable to exploitation by a malicious subsite administrator.
Based on public CVE data (MITRE/NVD).