PT-2026-7248 · WordPress+1 · Ninja Forms+1
Johska
·
Published
2026-02-10
·
Updated
2026-02-11
·
CVE-2026-2268
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Ninja Forms versions prior to 3.14.1
Description
The Ninja Forms plugin for WordPress is susceptible to Sensitive Information Exposure in versions up to and including 3.14.0. This occurs because the
ninja forms merge tags filter is applied unsafely to user-provided input within repeater fields, allowing the resolution of {post meta:KEY} merge tags without proper authorization. This enables unauthenticated attackers to retrieve arbitrary post metadata from any post on the site. The issue is exploitable via the nf ajax submit API endpoint and can expose sensitive data like WooCommerce billing emails, API keys, private tokens, and customer personal information.Recommendations
Update Ninja Forms to version 3.14.1 or later.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ninja Forms
Woocommerce