CVE-2026-65049: Incorrect Authorization in Saturday Drive Ninja Forms
Ninja Forms plugin for WordPress Multisite versions 3.14.8 and earlier contains an incorrect authorization vulnerability. This flaw allows a subsite Administrator to delete all Ninja Forms data network-wide by exploiting improper capability checks and unsafe multisite migration defaults. An attacker can send a crafted POST request to the admin-ajax.php endpoint to trigger deletion routines that affect every subsite without needing super-admin privileges. The vulnerability has a high severity rating with a CVSS score of 8.4.
AI Analysis
Technical Summary
CVE-2026-65049 is an incorrect authorization vulnerability in the Ninja Forms WordPress plugin (<=3.14.8) affecting multisite installations. The vulnerability arises from a site-scoped capability check combined with unsafe multisite migration defaults, allowing a subsite Administrator to invoke a crafted POST request to admin-ajax.php with the nf_delete_all_data action and a per-site nonce. This triggers migration routines that iterate over all blogs in the network using switch_to_blog(), unconditionally dropping all nf3_* tables and clearing options and transients across every subsite. This action does not require super-admin or network-admin privileges, enabling a subsite Administrator to cause network-wide data deletion.
Potential Impact
An attacker with subsite Administrator privileges can delete all Ninja Forms data across the entire WordPress multisite network. This includes dropping all nf3_* tables and clearing options and transients on every subsite, resulting in significant data loss and disruption of form functionality network-wide. The vulnerability does not require elevated network-wide privileges, increasing the risk of exploitation within multisite environments.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict subsite Administrator privileges where possible and monitor for suspicious POST requests to admin-ajax.php with the nf_delete_all_data action. Avoid using unsafe multisite migration defaults if configurable. Follow updates from Saturday Drive for an official patch or mitigation instructions.
CVE-2026-65049: Incorrect Authorization in Saturday Drive Ninja Forms
Description
Ninja Forms plugin for WordPress Multisite versions 3.14.8 and earlier contains an incorrect authorization vulnerability. This flaw allows a subsite Administrator to delete all Ninja Forms data network-wide by exploiting improper capability checks and unsafe multisite migration defaults. An attacker can send a crafted POST request to the admin-ajax.php endpoint to trigger deletion routines that affect every subsite without needing super-admin privileges. The vulnerability has a high severity rating with a CVSS score of 8.4.
CVSS v4.0
Score 8.4high
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-65049 is an incorrect authorization vulnerability in the Ninja Forms WordPress plugin (<=3.14.8) affecting multisite installations. The vulnerability arises from a site-scoped capability check combined with unsafe multisite migration defaults, allowing a subsite Administrator to invoke a crafted POST request to admin-ajax.php with the nf_delete_all_data action and a per-site nonce. This triggers migration routines that iterate over all blogs in the network using switch_to_blog(), unconditionally dropping all nf3_* tables and clearing options and transients across every subsite. This action does not require super-admin or network-admin privileges, enabling a subsite Administrator to cause network-wide data deletion.
Potential Impact
An attacker with subsite Administrator privileges can delete all Ninja Forms data across the entire WordPress multisite network. This includes dropping all nf3_* tables and clearing options and transients on every subsite, resulting in significant data loss and disruption of form functionality network-wide. The vulnerability does not require elevated network-wide privileges, increasing the risk of exploitation within multisite environments.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict subsite Administrator privileges where possible and monitor for suspicious POST requests to admin-ajax.php with the nf_delete_all_data action. Avoid using unsafe multisite migration defaults if configurable. Follow updates from Saturday Drive for an official patch or mitigation instructions.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-07-21T14:05:53.719Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a5f856e2a4a8d59894725ff
Added to database: 07/21/2026, 14:42:54 UTC
Last enriched: 07/30/2026, 09:37:14 UTC
Last updated: 09/04/2026, 22:52:14 UTC
Views: 40
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.