logo

CVE-2026-65049: Ninja Forms Multisite Flaw Enables Network-Wide Data Deletion

ID: 2747d881-bfe2-5a49-83a1-1ca4ca49ca32

STIX ID: report--2747d881-bfe2-5a49-83a1-1ca4ca49ca32

Feed Name: CosmicBytez Labs

Threat Score
78/100

Date Published: 2026-07-22

Date Updated: 2026-07-23

...
...

A critical (CVSS 9.3) incorrect-authorization vulnerability (CVE-2026-65049) in the Ninja Forms WordPress plugin allows a subsite administrator on WordPress Multisite to trigger a network-level migration/cleanup function without proper privilege checks, enabling deletion of all Ninja Forms forms, submissions, and settings across the entire multisite network. The report covers technical root cause, attack chain, affected scope, remediation steps (update to >3.14.8, audit admins, backups), detection indicators, and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.