Impact
The Ninja Forms – Excel Export plugin allows authenticated users with subscriber-level access to use the spreadsheet_export_form_id parameter without adequate validation. This leads to an insecure direct object reference where an attacker can supply arbitrary form IDs, causing the plugin to export the matching form’s submission data as an XLSX file. The exported data may contain names, email addresses, phone numbers, physical addresses and other personally identifiable information, resulting in a confidentiality breach.
Affected Systems
WordPress sites that have installed the Ninja Forms – Excel Export plugin from the SaturdayDrive vendor, versions 3.3.6 or earlier. Any site using the plugin within the affected version range is vulnerable.
Risk and Exploitability
The vulnerability carries a CVSS score of 4.3, indicating moderate severity, and an EPSS score of < 1%, meaning the likelihood of exploitation is flaw is not currently listed in the CISA KEV catalog. The attack vector is inferred to be a direct HTTP request to the plugin’s export endpoint where a user supplies a form ID. An attacker who has verified subscriber-level credentials can enumerate form IDs and download the corresponding data, achieving the full impact with minimal technical effort.
OpenCVE Enrichment