Impact
The Ninja Forms – Excel Export plugin for WordPress has a directory traversal flaw that lets an attacker with subscriber-level rights supply a malicious spreadsheet name. By manipulating the 'spreadsheet_export_tmp_name' parameter, the attacker can write or overwrite arbitrary *.xls or *.xlsx files anywhere the web server can write. This allows placement of malicious content or replacement of existing scripts, creating a vector for remote code execution or other destructive actions.
Affected Systems
The flaw affects all versions of the Ninja Forms – Excel Export plugin up to and including 3.3.6, supplied by SaturdayDrive. WordPress sites running those plugin versions, regardless of core WordPress version or server operating system, are vulnerable.
Risk and Exploitability
The CVSS score of 4.3 categorises the defect as medium severity, while the EPSS value of less than 1% suggests low likelihood of exploitation in the wild. Nevertheless, the vulnerability requires only authenticated subscriber access, a privilege many sites grant to regular users. If an attacker writes a malicious spreadsheet to a web‑servable location or overwrites a PHP script, remote code execution could be achieved. The issue is not currently listed in the CISA KEV catalog.
OpenCVE Enrichment