CVE-2026-2268Disclosure

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Ninja Forms plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.14.0. This is due to the unsafe application of the `ninja_forms_merge_tags` filter to user-supplied input within repeater fields, which allows the resolution of `{post_meta:KEY}` merge tags without authorization checks. This makes it possible for unauthenticated attackers to extract arbitrary post metadata from any post on the site, including sensitive data such as WooCommerce billing emails, API keys, private tokens, and customer personal information via the `nf_ajax_submit` AJAX action.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-200

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-02-11: 102-11
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
Full discourse1 post
  • RedPacket Security@RedPacketSec
    Disclosure

    CVE Alert: CVE-2026-2268 - kstover - Ninja Forms – The Contact Form Builder That Grows With You - https://www.redpacketsecurity.com/cve-alert-cve-2026-2268-kstover-ninja-forms-the-contact-form-builder-that-grows-with-you/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-2268 #kstover #ninja-forms-the-contact-form-builder-that-grows-with-you

    Post summary

    The post announces a CVE-2026-2268 alert for Ninja Forms and links to a security advisory website, but no technical or exploit details are provided.

    00000115
    3.5K followersView on X

Explore more