PT-2026-60702 · WordPress · Ninja Forms - Excel Export

CVE-2026-15159

·

Published

2026-07-17

·

Updated

2026-07-17

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Ninja Forms - Excel Export versions prior to 3.3.7
Description An Insecure Direct Object Reference occurs when an application provides direct access to objects based on user-supplied input. Authenticated attackers with subscriber-level access and above can enumerate form IDs and download all stored submission data, including personally identifiable information (PII) such as names, email addresses, phone numbers, and physical addresses, as an XLSX file. This is possible via the spreadsheet export form id parameter due to missing validation on a user-controlled key.
Recommendations Update Ninja Forms - Excel Export to version 3.3.7 or later. Avoid using the spreadsheet export form id parameter until the update is applied.

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-15159

Affected Products

Ninja Forms - Excel Export