CVE-2026-81772: WordPress Ninja Forms - Layout & Styles plugin <= 3.0.31 - PHP Object Injection vulnerability
Unauthenticated PHP Object Injection in Ninja Forms - Layout & Styles <= 3.0.31 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress/Ninja Forms - Layout & Stylesto a version that resolves this vulnerability.Fixed in 3.0.31
Event History
Frequently Asked Questions
Who can exploit this issue?
The vulnerability is unauthenticated, so an attacker does not need a WordPress account or plugin privileges. Exploitation does require user interaction, as indicated by the UI:R vector.
Which installations are affected?
WordPress sites using Ninja Forms - Layout & Styles version 3.0.31 or earlier are affected according to the provided advisory.
What is the potential impact of successful exploitation?
The supplied CVSS vector rates confidentiality, integrity, and availability impact as high. A successful attack could therefore affect data confidentiality, modify data or site behavior, and disrupt availability.