Description
The Ninja Forms - File Uploads plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.3.29. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to read all plugin debug log entries stored in the wp_nf3_log table or permanently delete all rows from that table.
Published: 2026-07-03
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Ninja Forms – File Uploads plugin for WordPress contains an authorization bypass flaw in the REST endpoints for debug-log/delete-all and debug-log/get-all. An unauthenticated user can exploit these endpoints because the plugin fails to verify that the requester has sufficient permissions to perform the action. This allows the attacker to read every entry stored in the wp_nf3_log table or to permanently delete exposing potentially sensitive debugging information and disrupting the plugin’s logging functionality.

Affected Systems

The affected product is Ninja Forms – File Uploads by SaturdayDrive. All versions up to and including 3.3.29 are vulnerable.

Risk and Exploitability

The CVSS base score of 5.3 indicates a moderate severity. The EPSS score of < 1 % reflects a very low but non‑zero probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Because the flaw can be exploited by any visitor to the site’s REST API without authentication, the risk is high in environments where the REST API is publicly reachable. An attacker can immediately read or erase debug log data, compromising confidentiality and integrity of debugging information within the affected site.

Generated by OpenCVE AI on July 21, 2026 at 10:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Ninja Forms – File Uploads plugin to version 3.3.30 or later.
  • If updating is not immediately possible, restrict access via a firewall and audit the wp_nf3_log table for unexpected deletions or unusual entries to detect potential abuse.
  • Disable debug mode in the plugin or remove the exposed debug‑log REST endpoints to eliminate the attack surface.

Generated by OpenCVE AI on July 21, 2026 at 10:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 03 Jul 2026 08:30:00 +0000

Type Values Removed Values Added
First Time appeared Saturdaydrive
Saturdaydrive ninja Forms - File Uploads
Wordpress
Wordpress wordpress
Vendors & Products Saturdaydrive
Saturdaydrive ninja Forms - File Uploads
Wordpress
Wordpress wordpress

Fri, 03 Jul 2026 05:30:00 +0000

Type Values Removed Values Added
Description The Ninja Forms - File Uploads plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.3.29. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to read all plugin debug log entries stored in the wp_nf3_log table or permanently delete all rows from that table.
Title Ninja Forms - File Uploads <= 3.3.29 - Missing Authorization to Unauthenticated Log Disclosure and Deletion via debug-log/delete-all and debug-log/get-all REST Endpoints
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Saturdaydrive Ninja Forms - File Uploads
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-07-06T16:32:44.790Z

Reserved: 2026-06-17T20:03:34.649Z

Link: CVE-2026-12557

cve-icon Vulnrichment

Updated: 2026-07-06T16:32:38.136Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T10:30:04Z

Weaknesses