CVE-2026-15550 The Ninja Forms - Save Progress plugin for WordPress… — CVE Notify — TG.ME

🚨 CVE-2026-15550
The Ninja Forms - Save Progress plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 3.0.30. This is due to the lack of capability checks and nonce verification in the 'bulk_actions' function. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary database records from the 'wp_nf3_objects' table, such as saved submissions.

🎖@cveNotify
Ninja Forms
Save Progress
Let users save WordPress form progress and continue later from any device. Add a save-and-continue button to any form in minutes. Works with Multi Step Forms.
September 5, 2026 33