Description
The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to unauthorized access of data due to a missing authorization check on the 'ninja-forms-views/token/refresh' REST callback in all versions up to, and including, 3.14.1. This makes it possible for unauthenticated attackers to view form submissions, which could potentially contain sensitive information.
Published: 2026-07-01
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Ninja Forms plugin for WordPress contains a missing authorization check on the 'ninja-forms-views/token/refresh' REST callback, allowing any unauthenticated user to retrieve form submissions that may include confidential information. This flaw is classified as CWE-862 and results in exposure of data that should be protected by authentication.

Affected Systems

All versions of the Ninja Forms plugin for WordPress up to and including 3.14.1, provided by kstover (Ninja Forms – The Contact Form Builder That Grows With You).

Risk and Exploitability

The CVSS score of 7.5 indicates high severity for information disclosure. The EPSS score is not available, so the exact likelihood of exploitation is unknown, but the flaw is reachable via a public REST endpoint that does not require authentication, making it readily exploitable by any web user. The vulnerability is not listed in CISA KEV, yet the publicly exposed endpoint presents a moderate to high risk for sites that rely on Ninja Forms to handle private data.

Generated by OpenCVE AI on July 1, 2026 at 12:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Ninja Forms plugin to a version that includes the authorization fix (≥3.14.2 if available).
  • Block unauthenticated access to the /wp-json/ninja-forms-views/token/refresh endpoint using a web application firewall or security plugin.
  • Monitor web server logs for requests to /wp-json/ninja-forms-views/token/refresh to detect potential exploitation attempts.

Generated by OpenCVE AI on July 1, 2026 at 12:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 01 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Kstover
Kstover ninja Forms – The Contact Form Builder That Grows With You
Wordpress
Wordpress wordpress
Vendors & Products Kstover
Kstover ninja Forms – The Contact Form Builder That Grows With You
Wordpress
Wordpress wordpress

Wed, 01 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 06:45:00 +0000

Type Values Removed Values Added
Description The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to unauthorized access of data due to a missing authorization check on the 'ninja-forms-views/token/refresh' REST callback in all versions up to, and including, 3.14.1. This makes it possible for unauthenticated attackers to view form submissions, which could potentially contain sensitive information.
Title Ninja Forms <= 3.14.1 - Missing Authorization to Unauthenticated Sensitive Information Disclosure via token/refresh REST Endpoint
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Kstover Ninja Forms – The Contact Form Builder That Grows With You
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-07-01T10:42:10.311Z

Reserved: 2026-01-20T17:56:47.784Z

Link: CVE-2026-1239

cve-icon Vulnrichment

Updated: 2026-07-01T10:33:28.400Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-01T14:30:05Z

Weaknesses