Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 22 Jul 2026 01:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Saturday Drive
Saturday Drive ninja Forms Wordpress Wordpress wordpress |
|
| Vendors & Products |
Saturday Drive
Saturday Drive ninja Forms Wordpress Wordpress wordpress |
Tue, 21 Jul 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ninjaforms
Ninjaforms ninja Forms |
|
| CPEs | cpe:2.3:a:ninjaforms:ninja_forms:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Ninjaforms
Ninjaforms ninja Forms |
Tue, 21 Jul 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 21 Jul 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Ninja Forms plugin version 3.14.8 and prior for WordPress Multisite contains an incorrect authorization vulnerability that allows a subsite Administrator to trigger network-wide deletion of all Ninja Forms data by exploiting a site-scoped capability check combined with unsafe multisite migration defaults. Attackers can send a crafted POST request to the admin-ajax.php endpoint with the nf_delete_all_data action and a per-site nonce to invoke migration routines that unconditionally iterate all blogs via switch_to_blog(), dropping all nf3_* tables and clearing options and transients across every subsite in the network without requiring super-admin or network-admin privileges. | |
| Title | Ninja Forms Cross-Site Network-Wide Data Deletion on WordPress Multisite via nf_delete_all_data AJAX Action | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-07-21T22:09:38.115Z
Reserved: 2026-07-21T14:05:53.719Z
Link: CVE-2026-65049
Updated: 2026-07-21T14:52:29.548Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-22T01:30:12Z