CVE-2026-65051
The Ninja Forms WordPress plugin version 3.14.8 has a security flaw that allows attackers to bypass form validation checks, even for unauthenticated users. By manipulating field metadata through the nopriv AJAX endpoint, attackers can override field types, remove required fields, and disable CAPTCHA checks, thereby allowing them to submit malicious content that can trigger actions such as sending email notifications or storing data in the database. This vulnerability can be exploited to inject unverified content into the system.
Based on public CVE data (MITRE/NVD).