Skip to content
Founder-led WordPress incident response and care Request an assessment
3zerodigital Request a Website Assessment

Plugin security history

Ninja Forms – The Contact Form Builder That Grows With You Vulnerability History & Security Timeline

The Wordfence Intelligence dataset currently contains 78 vulnerability records associated with Ninja Forms – The Contact Form Builder That Grows With You, published between 2014 and 2026.

Dataset last synchronized: 2026-08-02 09:41:47 UTC

At a glance

Security Snapshot

78Total records
4Critical
19High
55Medium
0Low
0Informational
78Patched records
0Currently marked unpatched
2014-11-06First disclosure
2026-07-23Latest disclosure
66 of 78CVE coverage

Year-by-Year Timeline

YearRecordsRelative volume
201433 records
201555 records
201644 records
201722 records
201877 records
201911 records
202055 records
202188 records
202277 records
202388 records
20241414 records
20251010 records
202644 records

Severity Breakdown

SeverityRecordsShare
Critical45.1%
High1924.4%
Medium5570.5%

Vulnerability-Type Breakdown

Cross-Site Scripting

35 records44.9%

First: 2014. Latest: 2025.

Other

15 records19.2%

First: 2015. Latest: 2025.

CSRF

8 records10.3%

First: 2020. Latest: 2025.

Missing Authorization

8 records10.3%

First: 2021. Latest: 2026.

SQL Injection

5 records6.4%

First: 2016. Latest: 2026.

Information Disclosure

5 records6.4%

First: 2021. Latest: 2026.

Arbitrary File Upload

1 record1.3%

First: 2016. Latest: 2016.

Path Traversal

1 record1.3%

First: 2023. Latest: 2023.

Patch Status

Patched
78
Currently marked unpatched
0
Unknown status
0

Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.

Latest Known Patched Versions

  • 3.14.10
  • 3.14.2
  • 3.14.1
  • 3.13.3
  • 3.12.1
  • 3.11.1
  • 3.10.2.2
  • 3.10.1
  • 3.8.25
  • 3.8.23
  • 3.8.20
  • 3.8.18
  • 3.8.16
  • 3.8.12
  • 3.8.11
  • 3.8.7
  • 3.8.5
  • 3.8.1
  • 3.7.2
  • 3.6.34
  • 3.6.26
  • 3.6.25
  • 3.6.22
  • 3.6.13
  • 3.5.8.4
  • 3.4.34.2
  • 3.3.21.4
  • 3.2.28
  • 3.1.10
  • 3.0.34.2
  • 3.6.11
  • 3.6.10
  • 3.6.8
  • 3.6.4
  • 3.5.8.2
  • 3.5.8
  • 3.4.34.1
  • 3.4.34
  • 3.4.27.1
  • 3.4.28
  • 3.4.24.2
  • 3.4.23
  • 3.3.21.2
  • 3.3.19.1
  • 3.3.18
  • 3.3.14
  • 3.3.9
  • 3.2.15
  • 3.2.14
  • 3.0.32

Affected-Version History

Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.

Affected rangeVulnerabilityPublishedPatched versionSeverity
*-3.14.9Ninja Forms <= 3.14.9 - Authenticated (Administrator+) SQL Injection via Import File 'settings' KeyJuly 23, 20263.14.10Medium
*-3.14.1Ninja Forms <= 3.14.1 - Missing Authorization to Unauthenticated Sensitive Information Disclosure via token/refresh REST EndpointJune 30, 20263.14.2High
*-3.14.1Ninja Forms <= 3.14.1 - Authenticated (Contributor+) Sensitive Information Disclosure via Block Editor TokenMarch 27, 20263.14.2Medium
*-3.14.0Ninja Forms <= 3.14.0 - Unauthenticated Information Disclosure in nf_ajax_submit AJAX ActionFebruary 9, 20263.14.1High
*-3.13.2Ninja Forms – The Contact Form Builder That Grows With You <= 3.13.2 - Insecure Direct Object Reference to Unauthenticated Sensitive Information Exposure via Unscoped Bearer TokenDecember 16, 20253.13.3High
*-3.13.2Ninja Forms <= 3.13.2 - Missing Authorization to Unauthenticated Submission DisclosureDecember 12, 20253.13.3High
*-3.12.0Ninja Forms – The Contact Form Builder That Grows With You <= 3.12.0 - Cross-Site Request Forgery to Plugin Settings UpdateSeptember 26, 20253.12.1Medium
*-3.12.0Ninja Forms – The Contact Form Builder That Grows With You <= 3.12.0 - Cross-Site Request Forgery to Limited File DeletionSeptember 26, 20253.12.1Medium
*-3.11.0Ninja Forms <= 3.11.0 - Unauthenticated PHP Object InjectionAugust 28, 20253.11.1High
*-3.10.2.1Ninja Forms <= 3.10.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via CSTIJune 26, 20253.10.2.2Medium
*-3.10.0Ninja Forms – The Contact Form Builder That Grows With You <= 3.10.0 - Authenticated (Admin+) Stored Cross-Site ScriptingApril 28, 20253.10.1Medium
*-3.10.0Ninja Forms – The Contact Form Builder That Grows With You <= 3.10.0 - Authenticated (Admin+) Stored Cross-Site ScriptingApril 28, 20253.10.1Medium
*-3.10.0Ninja Forms – The Contact Form Builder That Grows With You <= 3.10.0 - Authenticated (Admin+) Stored Cross-Site ScriptingApril 28, 20253.10.1Medium
*-3.8.24Ninja Forms – The Contact Form Builder That Grows With You <= 3.8.24 - Authenticated (Contributor+) Stored Cross-Site Scripting via ShortcodeJanuary 29, 20253.8.25Medium
*-3.8.22Ninja Forms – The Contact Form Builder That Grows With You <= 3.8.22 - Authenticated (Subscriber+) Arbitrary Shortcode ExecutionDecember 28, 20243.8.23Medium
*-3.8.19Ninja Forms – The Contact Form Builder That Grows With You <= 3.8.19 - Unauthenticated Stored Cross-Site Scripting via Form CalculationsDecember 11, 20243.8.20High
*-3.8.17Ninja Forms – The Contact Form Builder That Grows With You <= 3.8.17 - Authenticated (Admin+) Stored Cross-Site ScriptingOctober 28, 20243.8.18Medium
*-3.8.17Ninja Forms – The Contact Form Builder That Grows With You <= 3.8.17 - Authenticated (Admin+) Stored Cross-Site ScriptingOctober 28, 20243.8.18Medium
*-3.8.15Ninja Forms Contact Form <= 3.8.15 - Reflected Self-Based Cross-Site Scripting via RefererSeptember 24, 20243.8.16Medium
*-3.8.11Ninja Forms <= 3.8.11 - Authenticated (Administrator+) Stored Cross-Site ScriptingAugust 28, 20243.8.12Medium
3.8.6-3.8.10Ninja Forms – The Contact Form Builder That Grows With You <= 3.8.10 - Reflected Cross-Site ScriptingAugust 12, 20243.8.11Medium
*-3.8.6Ninja Forms <= 3.8.6 - Cross-Site Request ForgeryJuly 24, 20243.8.7Medium
*-3.8.4Ninja Forms <= 3.8.4 - Authenticated (Subscriber+) Arbitrary Shortcode ExecutionJuly 4, 20243.8.5Medium
*-3.8.0Ninja Forms – The Contact Form Builder That Grows With You <= 3.8.0 - Authenticated (Admin+) Stored Cross-Site ScriptingApril 8, 20243.8.1Medium
*-3.8.0Ninja Forms – The Contact Form Builder That Grows With You <= 3.8.0 - Authenticated (Admin+) Stored Cross-Site ScriptingApril 8, 20243.8.1Medium

Selected source records

Latest Records

MediumCVE-2026-15663

Ninja Forms <= 3.14.9 - Authenticated (Administrator+) SQL Injection via Import File 'settings' Key

Published: July 23, 2026

Affected versions
*-3.14.9
Patched versions
3.14.10
Original Wordfence record
HighCVE-2026-1239

Ninja Forms <= 3.14.1 - Missing Authorization to Unauthenticated Sensitive Information Disclosure via token/refresh REST Endpoint

Published: June 30, 2026

Affected versions
*-3.14.1
Patched versions
3.14.2
Original Wordfence record
MediumCVE-2026-1307

Ninja Forms <= 3.14.1 - Authenticated (Contributor+) Sensitive Information Disclosure via Block Editor Token

Published: March 27, 2026

Affected versions
*-3.14.1
Patched versions
3.14.2
Original Wordfence record
HighCVE-2026-2268

Ninja Forms <= 3.14.0 - Unauthenticated Information Disclosure in nf_ajax_submit AJAX Action

Published: February 9, 2026

Affected versions
*-3.14.0
Patched versions
3.14.1
Original Wordfence record
HighCVE-2025-11924

Ninja Forms – The Contact Form Builder That Grows With You <= 3.13.2 - Insecure Direct Object Reference to Unauthenticated Sensitive Information Exposure via Unscoped Bearer Token

Published: December 16, 2025

Affected versions
*-3.13.2
Patched versions
3.13.3
Original Wordfence record
HighCVE-2025-14072

Ninja Forms <= 3.13.2 - Missing Authorization to Unauthenticated Submission Disclosure

Published: December 12, 2025

Affected versions
*-3.13.2
Patched versions
3.13.3
Original Wordfence record
MediumCVE-2025-10499

Ninja Forms – The Contact Form Builder That Grows With You <= 3.12.0 - Cross-Site Request Forgery to Plugin Settings Update

Published: September 26, 2025

Affected versions
*-3.12.0
Patched versions
3.12.1
Original Wordfence record
MediumCVE-2025-10498

Ninja Forms – The Contact Form Builder That Grows With You <= 3.12.0 - Cross-Site Request Forgery to Limited File Deletion

Published: September 26, 2025

Affected versions
*-3.12.0
Patched versions
3.12.1
Original Wordfence record

Highest-Severity Records

CriticalCVE-2016-1209

Ninja Forms Contact Form 2.9.36 - 2.9.42 - Unauthenticated Arbitrary File Upload

Published: May 5, 2016

Affected versions
2.9.36-2.9.42
Patched versions
2.9.42.1
Original Wordfence record
CriticalCVE-2019-15025

Ninja Forms Contact Form <= 3.3.21.1 - SQL Injection

Published: January 7, 2019

Affected versions
*-3.3.21.1
Patched versions
3.3.21.2
Original Wordfence record
Critical

Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress <= 3.6.10 - Code Injection

Published: June 15, 2022

Affected versions
*-3.0.34.1; 3.1-3.1.9; 3.2-3.2.27; 3.3-3.3.21.3; 3.4-3.4.34.1; 3.5-3.5.8.3; 3.6-3.6.10
Patched versions
3.0.34.2, 3.1.10, 3.2.28, 3.3.21.4, 3.4.34.2, 3.5.8.4, 3.6.11
Original Wordfence record
CriticalCVE-2018-20981

Ninja Forms <= 3.3.8 - Insufficient Restrictions during Export Personal Data requests

Published: July 6, 2018

Affected versions
*-3.3.8
Patched versions
3.3.9
Original Wordfence record
HighCVE-2021-24163

Ninja Forms Contact Form <= 3.4.33 - Authenticated SendWP Plugin Installation and Client Secret Key Disclosure

Published: February 16, 2021

Affected versions
[*, 3.4.34)
Patched versions
3.4.34
Original Wordfence record
High

Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress <= 3.6.9 - Cross-Site Request Forgery to Field Import and PHP Object Injection

Published: June 7, 2022

Affected versions
*-3.6.9
Patched versions
3.6.10
Original Wordfence record
High

Ninja Forms Contact Form <= 2.9.55.1 - Authenticated SQL Injection

Published: August 16, 2016

Affected versions
[*, 2.9.55.2)
Patched versions
2.9.55.2
Original Wordfence record
HighCVE-2020-36174

Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress <= 3.4.27 - Cross-Site Request Forgery to Plugin Installation

Published: September 22, 2020

Affected versions
*-3.4.27
Patched versions
3.4.27.1
Original Wordfence record

View all associated vulnerabilities

Need help reviewing an exposed WordPress website?

Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.

Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.

Data Source, Attribution and Methodology

This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.

Return to the Security History Directory