Impact
The vulnerability allows a user with a specific Ninja Forms capability to perform a range of privileged actions through the plugin’s REST API. The API does not check that the capability is held only by administrators; instead it treats the capability as having full site administration rights. An attacker who obtains or is granted this capability can read the plugin’s settings and stored form submissions, overwrite configuration values, and create or modify arbitrary posts and pages. This enables direct tampering with site content, data theft, and the potential to embed malicious code or misleading information in the site’s front‑end.
Affected Systems
WordPress sites running the Ninja Forms plugin version 3.14.0 through 3.15.1 are affected. The vulnerability exists in all releases prior to 3.15.2. The affected capability is not assigned to any default WordPress role by the plugin; it must be explicitly granted by an administrator, often when delegating form builder access to other users.
Risk and Exploitability
The flaw can be exploited remotely via the REST API since no further authentication or authorization checks are performed on the capability. While the exploit requires a user to be granted the specific capability, the fact that the capability can be assigned to non‑administrator roles makes this vulnerability a significant risk if administrators incorrectly delegate building privileges. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, but the high impact of unauthorized site content modification warrants prompt remediation.
OpenCVE Enrichment