PT-2026-60702 · WordPress · Ninja Forms - Excel Export
CVE-2026-15159
·
Published
2026-07-17
·
Updated
2026-07-17
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Ninja Forms - Excel Export versions prior to 3.3.7
Description
An Insecure Direct Object Reference occurs when an application provides direct access to objects based on user-supplied input. Authenticated attackers with subscriber-level access and above can enumerate form IDs and download all stored submission data, including personally identifiable information (PII) such as names, email addresses, phone numbers, and physical addresses, as an XLSX file. This is possible via the
spreadsheet export form id parameter due to missing validation on a user-controlled key.Recommendations
Update Ninja Forms - Excel Export to version 3.3.7 or later.
Avoid using the
spreadsheet export form id parameter until the update is applied.Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ninja Forms - Excel Export