CVE · Critical

CVE-2026-65049 — Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] <= 3.14.8 (unfixed)

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-65049 Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] <= 3.14.8 (unfixed) Critical 9.3 < 3.14.8 3.14.8 2026-07-21

CVE-2026-65049

The Ninja Forms plugin for WordPress Multisite versions prior to 3.14.8 contains a security flaw that allows a subsite administrator to delete all Ninja Forms data across the entire network. This is possible because the plugin's authorization checks are flawed, allowing an attacker to send a specially crafted request to the admin-ajax.php endpoint, which then triggers a migration routine that deletes data from all subsites in the network. The deletion process is not restricted to super-admin or network-admin privileges, making it vulnerable to exploitation by a malicious subsite administrator.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.