Impact
Ninja Forms versions up to 3.14.6 are vulnerable to PHP Object Injection via the form import feature. An authenticated attacker who has at least administrator privileges can submit a specially crafted form that is deserialized by the plugin during import. Because the deserialization occurs automatically when the import is performed, the attacker does not need any additional interaction. The core vulnerability itself does not provide a ready‑to‑execute persistence or code‑execution (POP) chain, so on a plain system the impact is limited to the ability to inject a PHP object. However, if the target site also hosts another plugin or theme that contains a usable POP chain, the injected object can be leveraged to delete arbitrary files, exfiltrate data, or execute arbitrary code, effectively giving the attacker full control over the affected server.
Affected Systems
The affected product is the Ninja Forms plugin for WordPress, versions 3.14.6 and earlier. No specific WordPress core version or theme is listed as affected by the deserialization flaw itself. The flaw becomes dangerous only when combined with a POP chain provided by additional installed plugins or themes.
Risk and Exploitability
The CVSS score of 6.6 indicates a moderate severity that balances a limited initial effect with the potential for significant damage if a POP chain is present. EPSS data is not available, so the current exploitation probability is unknown. The vulnerability is not listed in the CISA KEV catalog. Attackers must have administrator or higher-level credentials to perform the import; no network or local privilege escalation is required beyond the existing role. If a compatible POP chain is present on the same site, the attacker can achieve arbitrary code execution, otherwise the effect remains limited to object creation during import.
OpenCVE Enrichment