Impact
The Ninja Forms – File Uploads plugin for WordPress contains an authorization bypass flaw in the REST endpoints for debug-log/delete-all and debug-log/get-all. An unauthenticated user can exploit these endpoints because the plugin fails to verify that the requester has sufficient permissions to perform the action. This allows the attacker to read every entry stored in the wp_nf3_log table or to permanently delete exposing potentially sensitive debugging information and disrupting the plugin’s logging functionality.
Affected Systems
The affected product is Ninja Forms – File Uploads by SaturdayDrive. All versions up to and including 3.3.29 are vulnerable.
Risk and Exploitability
The CVSS base score of 5.3 indicates a moderate severity. The EPSS score of < 1 % reflects a very low but non‑zero probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Because the flaw can be exploited by any visitor to the site’s REST API without authentication, the risk is high in environments where the REST API is publicly reachable. An attacker can immediately read or erase debug log data, compromising confidentiality and integrity of debugging information within the affected site.
OpenCVE Enrichment