CyberRota
← Ana sayfaya dön

CVE-2026-65050

MEDIUM · CVSS 6.5

Kaynak: NVD + CISA KEV + EPSS · Yayınlanma: 2026-07-21T15:16:39.147 · Çekilme zamanı: 2026-07-21T18:27:46.742150+00:00

CyberRota Yorumu

Detaylı analiz gerekiyor.

CVE
CVE-2026-65050
Severity
MEDIUM
CVSS
6.5
EPSS
Yok
WordPress

Orijinal NVD Açıklaması

Ninja Forms WordPress plugin version 3.14.8 and prior contains a missing authorization vulnerability in the render callback of the `ninja-forms/submissions-table` Gutenberg block that allows authenticated attackers with Author-level privileges to expose stored form submissions to unauthenticated visitors by embedding the block with an arbitrary formID on a published post. Attackers can retrieve the signed bearer token injected into every page visitor's browser via `wp_localize_script` and use it against the REST API submissions endpoint to access all saved form submission field values, including sensitive personally identifiable information such as names, email addresses, and phone numbers.