SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-80438

MEDIUM · CVSS 5.9 EPSS 0.14%

Source: NVD + CISA KEV + EPSS · Published 2026-09-04 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The Ninja Forms WordPress plugin prior to version 3.15.2 has a vulnerability that allows users with a specific capability, not tied to any default WordPress role, to perform administrative actions such as reading settings, accessing stored submissions, and modifying site content. This flaw poses a significant risk as it can lead to unauthorized data exposure and site manipulation. WordPress administrators who have delegated access to the form builder should prioritize updating to the latest version to mitigate potential exploitation.

CVE
CVE-2026-80438
Severity
MEDIUM
CVSS
5.9
EPSS
0.14%
WordPress

Original NVD Description

The Ninja Forms WordPress plugin before 3.15.2 does not restrict its REST abilities to administrators, accepting a Ninja Forms WordPress plugin before 3.15.2-specific capability as equivalent to full site administration, which allows any user granted that capability to read Ninja Forms WordPress plugin before 3.15.2 settings and stored form submissions, overwrite the Ninja Forms WordPress plugin before 3.15.2's configuration, and create or modify arbitrary posts and pages. The capability belongs to no default WordPress role and the Ninja Forms WordPress plugin before 3.15.2 never grants it, so an administrator must have assigned it, typically when delegating access to the form builder.