Pricing
Solutions
WordPress security
Instantly fix and mitigate vulnerabilities
Plugin auditing
Paid auditing for WordPress vendors
Managed VDP
Start a security program for your plugins
Bug Bounty
Join the community and earn bounties
Enterprise API
At scale monitoring and vPatching for hosts
Vulnerability database
The latest WordPress security intelligence
Login
Start trial
Ninja Forms
Kevin Stover
Developer
3.13.1
Latest version
600,000
Installations
6 days ago
Last updated
WordPress Plugin
No VDP
See changelog
Claim ownership
Report vulnerability
Vulnerabilities
Vulnerability history
0 present
57 fixed
16 Mitigation rules
Cross-Site Request Forgery to Limited File Deletion vulnerability
<= 3.12.0
Sep 26, 2025
Cross-Site Request Forgery to Plugin Settings Update vulnerability
<= 3.12.0
Sep 26, 2025
Unauthenticated PHP Object Injection vulnerability
< 3.11.1
Sep 9, 2025
Authenticated (Contributor+) Stored Cross-Site Scripting via CSTI vulnerability
<= 3.10.2.1
Jun 26, 2025
Admin+ Stored XSS vulnerability
< 3.10.1
May 19, 2025
Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode vulnerability
<= 3.8.24
Jan 30, 2025
Authenticated (Subscriber+) Arbitrary Shortcode Execution vulnerability
<= 3.8.22
Dec 30, 2024
Unauthenticated Stored Cross-Site Scripting via Form Calculations vulnerability
<= 3.8.19
Dec 12, 2024
Cross Site Scripting (XSS) vulnerability
<= 3.8.16
Oct 28, 2024
Cross Site Scripting (XSS) vulnerability
<= 3.8.16
Oct 28, 2024
Reflected Self-Based Cross-Site Scripting via Referer vulnerability
<= 3.8.15
Sep 25, 2024
Wordpress Ninja Forms plugin 3.8.6 - 3.8.10 - Reflected XSS
3.8.6-3.8.10
Sep 3, 2024
Cross Site Scripting (XSS) vulnerability
<= 3.8.11
Aug 28, 2024
Cross Site Request Forgery (CSRF) vulnerability
<= 3.8.6
Jul 24, 2024
Subscriber+ Arbitrary Shortcode Execution vulnerability
<= 3.8.4
Jul 4, 2024
Cross-Site Request Forgery to Publicly Accessible Form Submission Export vulnerability
<= 3.8.0
Mar 29, 2024
Authenticated (Author+) Stored Cross-Site Scripting vulnerability
<= 3.8.0
Mar 29, 2024
Unauthenticated Second Order SQL Injection vulnerability
<= 3.7.1
Feb 1, 2024
Admin+ Stored XSS vulnerability
< 3.6.34
Nov 7, 2023
Reflected Cross Site Scripting (XSS) vulnerability
<= 3.6.25
Jul 25, 2023
Subscriber+ Broken Access Control vulnerability
<= 3.6.25
Jul 25, 2023
Contributor+ Broken Access Control vulnerability
<= 3.6.25
Jul 25, 2023
Denial of Service Attack vulnerability
<= 3.6.25
Jul 7, 2023
Arbitrary File Deletion vulnerability
<= 3.6.24
Jun 22, 2023
Reflected XSS vulnerability
< 3.6.22
May 2, 2023
Authenticated PHP Objection Injection vulnerability
<= 3.6.12
Sep 5, 2022
Unauthenticated PHP Object Injection vulnerability
<= 3.6.10
Jun 15, 2022
Authenticated Stored Cross-Site Scripting (XSS) vulnerability
<= 3.6.9
Jun 13, 2022
Authenticated Stored Cross-Site Scripting (XSS) vulnerability
<= 3.6.9
Jun 10, 2022
Authenticated Stored Cross-Site Scripting (XSS) vulnerability
<= 3.6.9
Jun 7, 2022
Unauthenticated Email Address Disclosure vulnerability
<= 3.6.7
Mar 22, 2022
SQL Injection (SQLi) vulnerability
<= 3.6.3
Oct 26, 2021
Stored Cross-Site Scripting (XSS) vulnerability
<= 3.5.8.1
Sep 27, 2021
Unprotected REST-API to Sensitive Information Disclosure vulnerability
<= 3.5.7
Sep 22, 2021
Unprotected REST-API to Email Injection vulnerability
<= 3.5.7
Sep 22, 2021
Cross-Site Request Forgery (CSRF) vulnerability
<= 3.4.33
Feb 16, 2021
Administrator Open Redirect vulnerability
<= 3.4.33
Feb 16, 2021
Authenticated OAuth Connection Key Disclosure vulnerability
<= 3.4.33
Feb 16, 2021
Authenticated SendWP Plugin Installation and Client Secret Key Disclosure vulnerability
<= 3.4.33
Feb 16, 2021
Cross-Site Request Forgery (CSRF) leading to Arbitrary Plugin Installation vulnerability
<= 3.4.27
Sep 22, 2020
Cross-Site Scripting (XSS) vulnerability
<= 3.3.21
Jun 25, 2019
SQL injection (SQLi) vulnerability
<= 3.3.21
Jun 25, 2019
Authenticated Open Redirect vulnerability
<= 3.3.19
Dec 4, 2018
Unauthenticated Cross-Site Scripting (XSS) vulnerability
<= 3.3.17
Nov 15, 2018
CSV Injection vulnerability
<= 3.3.13
Aug 28, 2018
Cross-Site Scripting (XSS) vulnerability
<= 3.3.13
Aug 28, 2018
Cross-Site Scripting (XSS) vulnerability
<= 3.2.13
Feb 22, 2018
Authenticated SQL Injection
<= 2.9.55.1
Aug 16, 2016
Multiple Cross Site Scripting
<= 2.9.51
Jul 19, 2016
PHP Object Injection
<= 2.9.42.0
Dec 26, 2015
Malicious File Export
<= 2.9.27
Sep 30, 2015
Cross Site Scripting
<= 2.9.21
Aug 4, 2015
Cross Site Scripting
<= 2.9.18
Jun 5, 2015
Cross Site Scripting
<= 2.9.10
Apr 20, 2015
Multiple XSS
<= 2.8.8
Mar 5, 2015
Unspecified Vulnerability
<= 2.8.9
Mar 5, 2015
Authorization Bypass
<= 2.7.7
Sep 8, 2014