Impact
Ninja Forms 3.14.8 performs a client‑controlled merge of field metadata into the server‑loaded form definition before running validation. An attacker can override field types, remove required flags, and disable CAPTCHA checks by sending crafted AJAX data to the nopriv endpoint. This allows unrestricted, unauthenticated submissions that can trigger email notifications or database storage with attacker‑controlled content.
Affected Systems
WordPress sites running the Ninja Forms plugin version 3.14.8. The product is part of Saturday Drive’s Ninja Forms line, identified by the provided CPE string. Administrators should verify whether this exact version is in use and consider upgrading.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate severity. The EPSS score of < 1% suggests a low likelihood of exploitation, and the issue is not listed in CISA’s KEV catalog. The publicly accessible nopriv AJAX endpoint provides a remote unauthenticated attack vector that could be used by stealthy actors to inject arbitrary content into forms.
OpenCVE Enrichment