CVE-2026-1307 describes a Sensitive Information Exposure vulnerability in the Ninja Forms plugin for WordPress, affecting all versions up to and including 3.14.1. This medium-severity flaw allows authenticated attackers with Contributor-level access or higher to gain an authorization token, enabling them to view form submissions that may contain sensitive information. The attack can be executed over the network with low complexity and low privileges, resulting in a high confidentiality impact. There is currently no evidence of active exploitation, and no public exploit code or proof-of-concept is available. Community discussion and media coverage regarding this vulnerability are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Kstover | Ninja Forms – The Contact Form Builder That Grows With You | >= 0, <= 3.14.1CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.