SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-15550

MEDIUM · CVSS 4.3 EPSS 0.16%

Source: NVD + CISA KEV + EPSS · Published 2026-09-05 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The Ninja Forms - Save Progress plugin for WordPress is susceptible to a missing authorization vulnerability, allowing authenticated attackers with subscriber-level access or higher to execute arbitrary deletions in the 'wp_nf3_objects' database table. This could lead to the loss of critical data, such as saved form submissions. WordPress site administrators using this plugin should prioritize applying updates to mitigate the risk of data loss.

CVE
CVE-2026-15550
Severity
MEDIUM
CVSS
4.3
EPSS
0.16%
WordPress

Original NVD Description

The Ninja Forms - Save Progress plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 3.0.30. This is due to the lack of capability checks and nonce verification in the 'bulk_actions' function. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary database records from the 'wp_nf3_objects' table, such as saved submissions.