GHSA-c8hw-hm2h-46fpMediumCVSS 4.3
The Ninja Forms - Excel Export plugin for WordPress is vulnerable to Insecure Direct Object...
🔗 CVE IDs covered (1)
📋 Description
The Ninja Forms - Excel Export plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.3.6 via the 'spreadsheet_export_form_id' parameter due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with subscriber-level access and above, to enumerate any Ninja Forms form ID and download all stored submission data — including names, email addresses, phone numbers, physical addresses, and any other PII collected by site forms — as a downloadable XLSX file.
🔗 References (4)
- https://nvd.nist.gov/vuln/detail/CVE-2026-15159
- https://plugins.trac.wordpress.org/browser/ninja-forms-excel-export/trunk/ninja-forms-excel-export.php#L187
- https://www.wordfence.com/threat-intel/vulnerabilities/id/783ccf21-db16-4aac-9a3c-992b3aac5526?source=cve
- https://github.com/advisories/GHSA-c8hw-hm2h-46fp