CyberRota Analysis
AI-GeneratedThe Ninja Forms - Excel Export plugin for WordPress is vulnerable due to an Insecure Direct Object Reference, allowing authenticated users with subscriber-level access and above to exploit the 'spreadsheet_export_form_id' parameter. This vulnerability enables attackers to enumerate form IDs and download sensitive submission data, including personally identifiable information (PII) such as names and email addresses, in an XLSX format. WordPress site administrators using this plugin should prioritize patching to mitigate the risk of data exposure.
Original NVD Description
The Ninja Forms - Excel Export plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.3.6 via the 'spreadsheet_export_form_id' parameter due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with subscriber-level access and above, to enumerate any Ninja Forms form ID and download all stored submission data — including names, email addresses, phone numbers, physical addresses, and any other PII collected by site forms — as a downloadable XLSX file.