CVE-2026-65049: Ninja Forms Cross-Site Network-Wide Data Deletion on WordPress Multisite via nf_delete_all_data AJAX Action
Ninja Forms plugin version 3.14.8 and prior for WordPress Multisite contains an incorrect authorization vulnerability that allows a subsite Administrator to trigger network-wide deletion of all Ninja Forms data by exploiting a site-scoped capability check combined with unsafe multisite migration defaults. Attackers can send a crafted POST request to the admin-ajax.php endpoint with the nfdeletealldata action and a per-site nonce to invoke migration routines that unconditionally iterate all blogs via switchtoblog(), dropping all nf3 tables and clearing options and transients across every subsite in the network without requiring super-admin or network-admin privileges.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-65049?
CVE-2026-65049 has a critical severity rating of 9.3.
How do I fix CVE-2026-65049?
To fix CVE-2026-65049, update the Ninja Forms plugin to version 3.14.9 or later.
Who is affected by CVE-2026-65049?
CVE-2026-65049 affects WordPress Multisite installations using Ninja Forms version 3.14.8 or earlier.
What kind of vulnerability is CVE-2026-65049?
CVE-2026-65049 is an incorrect authorization vulnerability that allows unauthorized data deletion across the multisite.
What is the impact of CVE-2026-65049?
The impact of CVE-2026-65049 is the potential network-wide deletion of all Ninja Forms data by a subsite Administrator.