PT-2026-84691 · WordPress · Ninja Forms - Layout & Styles
CVE-2026-81772
·
Published
2026-09-02
·
Updated
2026-09-03
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Ninja Forms - Layout & Styles versions prior to 3.0.32
Description
An unauthenticated PHP Object Injection exists in the plugin. PHP Object Injection is a vulnerability that occurs when untrusted input is passed to the PHP
unserialize() function, potentially allowing an attacker to manipulate object properties or execute arbitrary code.Recommendations
Update Ninja Forms - Layout & Styles to version 3.0.32 or later.
Fix
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ninja Forms - Layout & Styles