WordPress security changelog
MEDIUM CVE-2026-80438 Deferred

Ninja Forms treats a delegated plugin capability as site administration

Ninja Forms versions 3.14.0 through 3.15.1 accept a Ninja Forms-specific capability as equivalent to full site administration. A user explicitly granted that non-default capability can read settings and stored submissions, overwrite plugin configuration, and create or modify arbitrary posts and pages.

CVE / CNA score 5.9 CVSS 3.1 · 134c704f-9b21-4f2e-91b3-4a467353bcc0
NVD score Pending NVD has not published its own CVSS assessment.
Component
Ninja Forms
Plugin slug
ninja-forms
Affected
3.14.0 to < 3.15.2
Safe version
3.15.2
Published
Sep 04, 2026
Weakness
CWE-284 — Improper Access Control

This CVE was published Sep 04, 2026 and is one of 74 known issues for this plugin.

Update, patch or deactivate.

Update to 3.15.2 or later and review users granted delegated Ninja Forms capabilities, stored submissions, settings, posts, and pages for unauthorized access or changes.

A safe version is available, so updating to that version or later is the preferred remediation. If an immediate update is not practical, consider a targeted application patch or temporarily restricting the affected functionality.

Deactivate only when warranted by your risk profile, or when advised by your hosting provider in the limited circumstances where the vulnerability cannot otherwise be mitigated. If you’re unsure which action is appropriate, contact Fused or your hosting provider for guidance.

Technical description

The Ninja Forms WordPress plugin before 3.15.2 does not restrict its REST abilities to administrators, accepting a Ninja Forms WordPress plugin before 3.15.2-specific capability as equivalent to full site administration, which allows any user granted that capability to read Ninja Forms WordPress plugin before 3.15.2 settings and stored form submissions, overwrite the Ninja Forms WordPress plugin before 3.15.2's configuration, and create or modify arbitrary posts and pages. The capability belongs to no default WordPress role and the Ninja Forms WordPress plugin before 3.15.2 never grants it, so an administrator must have assigned it, typically when delegating access to the form builder.

CVE / CNA vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:N

Primary and upstream sources