
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-1307 is a Sensitive Information Exposure vulnerability in the Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress, classified under CWE-200. It affects all versions up to and including 3.14.1, allowing authenticated attackers with Contributor-level access or above to obtain an authorization token that grants access to form submissions for arbitrary forms. The vulnerability was published on March 28, 2026, and assigned by Wordfence. It carries a CVSS v3.1 base score of 6.5 (Medium) (Wordfence, Red Hat CVE).
The root cause is improper exposure of sensitive information (CWE-200) via a callback function registered for the admin_enqueue_scripts action handler located in blocks/bootstrap.php. This callback inadvertently exposes an authorization token to users with at least Contributor-level WordPress roles, which can then be used to retrieve form submissions from any Ninja Forms form on the site. The attack vector is network-based, requires low privileges, no user interaction, and has low attack complexity. A patch was committed to the plugin's SVN repository (Plugin Changeset, Wordfence).
Successful exploitation results in a high confidentiality impact with no effect on integrity or availability. An authenticated attacker with Contributor-level access can harvest the exposed authorization token and use it to view form submissions across all forms on the WordPress site, potentially exposing personally identifiable information (PII), contact details, or other sensitive user-submitted data. The scope is limited to the affected WordPress instance, but the breadth of data accessible via arbitrary form submissions makes this a meaningful data exposure risk (Wordfence, Red Hat CVE).
No public exploit code or active in-the-wild exploitation has been reported for CVE-2026-1307 as of the available data. The EPSS score is approximately 0.031% (0.000310), indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires at minimum a Contributor-level WordPress account, which limits the attack surface compared to unauthenticated vulnerabilities (Wordfence).
admin_enqueue_scripts action fires automatically, causing blocks/bootstrap.php to expose an authorization token in the page's JavaScript or enqueued script data./wp-admin/) by Contributor-level accounts, particularly if followed by API calls to Ninja Forms submission endpoints./wp-json/ninja-forms/v1/submissions) originating from Contributor-level user sessions or from unexpected IP addresses.Site administrators should update the Ninja Forms plugin to version 3.14.2 or later, which addresses the token exposure in blocks/bootstrap.php (Plugin Changeset). As a temporary workaround, restrict Contributor-level user registrations or audit existing Contributor accounts to minimize the pool of potential attackers. Additionally, review WordPress user roles and remove unnecessary Contributor accounts until the patch can be applied (Wordfence).
Wordfence included CVE-2026-1307 in their weekly WordPress vulnerability report for the period of March 23–29, 2026, and Sucuri highlighted it in their March 2026 vulnerability patch roundup (Wordfence Blog, Sucuri Blog). Community reaction has been relatively muted given the medium severity and the requirement for authenticated access, with no notable threat actor attribution or significant social media discussion observed.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."