CVE-2026-15159: Ninja Forms - Excel Export <= 3.3.6 - Insecure Direct Object Reference to Authenticated (Subscriber+) Sensitive Data Disclosure via 'spreadsheet_export_form_id' Parameter
The Ninja Forms - Excel Export plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.3.6 via the 'spreadsheetexportformid' parameter due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with subscriber-level access and above, to enumerate any Ninja Forms form ID and download all stored submission data — including names, email addresses, phone numbers, physical addresses, and any other PII collected by site forms — as a downloadable XLSX file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-15159?
CVE-2026-15159 has a medium severity rating of 4.3.
How do I fix CVE-2026-15159?
To fix CVE-2026-15159, update the Ninja Forms Excel Export plugin to version 3.3.7 or later.
What type of vulnerability is CVE-2026-15159?
CVE-2026-15159 is an Insecure Direct Object Reference vulnerability.
Who is affected by CVE-2026-15159?
Authenticated attackers with Subscriber+ privileges can exploit CVE-2026-15159 to disclose sensitive data.
What is the impact of CVE-2026-15159?
CVE-2026-15159 allows attackers to gain unauthorized access to sensitive data through the 'spreadsheet_export_form_id' parameter.