CVE-2026-65049 Details
Description
Ninja Forms plugin version 3.14.8 and prior for WordPress Multisite contains an incorrect authorization vulnerability that allows a subsite Administrator to trigger network-wide deletion of all Ninja Forms data by exploiting a site-scoped capability check combined with unsafe multisite migration defaults. Attackers can send a crafted POST request to the admin-ajax.php endpoint with the nf_delete_all_data action and a per-site nonce to invoke migration routines that unconditionally iterate all blogs via switch_to_blog(), dropping all nf3_* tables and clearing options and transients across every subsite in the network without requiring super-admin or network-admin privileges.
An incorrect authorization vulnerability has been identified in the Ninja Forms plugin for WordPress Multisite, affecting versions through 3.14.8. This vulnerability allows a subsite Administrator to initiate a network-wide deletion of all Ninja Forms data. The issue arises from a site-scoped capability check that is exploited to bypass authorization, combined with unsafe defaults during multisite migrations. By sending a crafted POST request to the admin-ajax.php endpoint with the nf_delete_all_data action and a per-site nonce, an attacker can invoke migration routines that unconditionally iterate through all blogs. This process drops all nf3_* tables and clears options and transients across every subsite in the network, all without the need for super-admin or network-admin privileges.
Users are advised to update the Ninja Forms plugin to version 3.14.9 or later, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 21, 2026CISA-ADP
Assessed Jul 21, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-863 | Incorrect Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Ninja Forms | <= 3.14.8 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 21, 2026 | CVE Modified | CISA-ADP |
| Jul 21, 2026 | New CVE Received | [email protected] |
Volerion