WordPress · Ninja Forms - File Uploads · CVE-2026-12557
**Name of the Vulnerable Software and Affected Versions**
Ninja Forms - File Uploads versions prior to 3.3.30
**Description**
An authorization bypass exists because the plugin fails to properly verify if a user is authorized to perform specific actions. This allows unauthenticated attackers to read all debug log entries stored in the `wp nf3 log` table or permanently delete all rows from that table. The issue is triggered via the 'debug-log/get-all' and 'debug-log/delete-all' API endpoints.
**Recommendations**
Update Ninja Forms - File Uploads to a version newer than 3.3.29.