Back to overview

CVE-2026-65051

MEDIUM
6.5
CVSS 3.1
Description
Ninja Forms WordPress plugin version 3.14.8 contains a client-side enforcement of server-side security vulnerability that allows unauthenticated attackers to bypass all form validation by merging attacker-controlled field metadata over server-loaded form definitions before validation runs. Attackers can craft a malicious AJAX submission overriding field types, removing required flags, and disabling CAPTCHA checks through the nopriv AJAX endpoint to trigger form actions such as email notifications and database storage with unverified, attacker-controlled content.

Metadata

CVE ID
CVE-2026-65051
State
PUBLISHED
Assigner
VulnCheck
Reserved
2026-07-21 14:05 UTC
Published
2026-07-21 14:31 UTC
Last updated
2026-07-21 14:31 UTC
Primary CWE
CWE-602
Client-Side Enforcement of Server-Side Security
Vendor / Product
Saturday Drive / Ninja Forms
Sources
cve.org  ·  NVD

Severity & Metrics

6.5 MEDIUM CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Affected products (1)
VendorProductPlatformVersions
Saturday Drive Ninja Forms 0 < 3.14.9, 3.14.9
Weakness (CWE)
CWESourceDescription
CWE-602 cna Client-Side Enforcement of Server-Side Security
CVSS scores (2)
ScoreSeverityVersionSourceVector
6.9 MEDIUM 4.0 cna CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N
6.5 MEDIUM 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Back to overview