CyberRota Analysis
AI-GeneratedThe Ninja Forms - Save Progress plugin for WordPress is susceptible to a missing authorization vulnerability, allowing authenticated attackers with subscriber-level access or higher to execute arbitrary deletions in the 'wp_nf3_objects' database table. This could lead to the loss of critical data, such as saved form submissions. WordPress site administrators using this plugin should prioritize applying updates to mitigate the risk of data loss.
Original NVD Description
The Ninja Forms - Save Progress plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 3.0.30. This is due to the lack of capability checks and nonce verification in the 'bulk_actions' function. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary database records from the 'wp_nf3_objects' table, such as saved submissions.