SEPTEMBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-15159

MEDIUM · CVSS 4.3 EPSS 0.18%

Source: NVD + CISA KEV + EPSS · Published 2026-07-17 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The Ninja Forms - Excel Export plugin for WordPress is vulnerable due to an Insecure Direct Object Reference, allowing authenticated users with subscriber-level access and above to exploit the 'spreadsheet_export_form_id' parameter. This vulnerability enables attackers to enumerate form IDs and download sensitive submission data, including personally identifiable information (PII) such as names and email addresses, in an XLSX format. WordPress site administrators using this plugin should prioritize patching to mitigate the risk of data exposure.

CVE
CVE-2026-15159
Severity
MEDIUM
CVSS
4.3
EPSS
0.18%
WordPress

Original NVD Description

The Ninja Forms - Excel Export plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.3.6 via the 'spreadsheet_export_form_id' parameter due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with subscriber-level access and above, to enumerate any Ninja Forms form ID and download all stored submission data — including names, email addresses, phone numbers, physical addresses, and any other PII collected by site forms — as a downloadable XLSX file.