CVE-2026-65049

Ninja Forms Cross-Site Network-Wide Data Deletion on WordPress Multisite via nf_delete_all_data AJAX Action

Ninja Forms plugin version 3.14.8 and prior for WordPress Multisite contains an incorrect authorization vulnerability that allows a subsite Administrator to trigger network-wide deletion of all Ninja Forms data by exploiting a site-scoped capability check combined with unsafe multisite migration defaults. Attackers can send a crafted POST request to the admin-ajax.php endpoint with the nf_delete_all_data action and a per-site nonce to invoke migration routines that unconditionally iterate all blogs via switch_to_blog(), dropping all nf3_* tables and clearing options and transients across every subsite in the network without requiring super-admin or network-admin privileges.


We have discovered 128,705 live websites that are affected by CVE-2026-65049.

Run a Free Instant Scan




Affected Software

Product  Ninja Forms
Category Form Builders
Vulnerable Domains128,705 live websites (100% of Ninja Forms install base)
Vulnerable Versions
  • from 0 through 3.14.9
Vulnerable Versions Count238 versions ( 100% of all versions)



Details

  • Published - Jul 21, 2026
  • Updated - Jul 22, 2026

Credits

  • Pavel Kohout, Aisle Research (finder)

Website Distribution by Country

Number of websites using CVE-2026-65049
United States57,589 websites



Germany11,974 websites
GB8,890 websites
France6,767 websites
Netherlands5,331 websites
Canada3,881 websites
Australia3,531 websites
Italy2,891 websites
Spain2,567 websites
Switzerland2,181 websites

Website Distribution by TLD

Number of websites using CVE-2026-65049
.com62,783 websites
.org8,821 websites
.de7,763 websites
.co.uk5,994 websites
.nl4,889 websites
.com.au3,236 websites
.fr3,191 websites
.net2,769 websites
.ca2,270 websites
.it1,924 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-65049

Top websites that are affected by CVE-2026-65049. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
****.com United States***
****.org United States*,***
****.ca United States*,***
**********.com United States*,***
***********.com United States*,***
****************.com United States*,***
***************.org GB*,***
****************.com United States*,***
**********.de Germany*,***
************.com United States**,***
See full domain list

FAQ

A total of 128,705 websites have been identified as vulnerable to CVE-2026-65049, based on global website indexing conducted by WebTechSurvey.
The Ninja Forms is affected by the CVE-2026-65049 vulnerability.
Ninja Forms versions up to 3.14.9 are vulnerable to CVE-2026-65049.
CVE-2026-65049 is resolved in version 3.14.9 of Ninja Forms.