Ninja Forms plugin version 3.14.8 and prior for WordPress Multisite contains an incorrect authorization vulnerability that allows a subsite Administrator to trigger network-wide deletion of all Ninja Forms data by exploiting a site-scoped capability check combined with unsafe multisite migration defaults. Attackers can send a crafted POST request to the admin-ajax.php endpoint with the nf_delete_all_data action and a per-site nonce to invoke migration routines that unconditionally iterate all blogs via switch_to_blog(), dropping all nf3_* tables and clearing options and transients across every subsite in the network without requiring super-admin or network-admin privileges.
We have discovered 128,705 live websites that are affected by CVE-2026-65049.
| Product | |
| Category | Form Builders |
| Vulnerable Domains | 128,705 live websites (100% of Ninja Forms install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 238 versions ( 100% of all versions) |
| 57,589 websites | |
| 11,974 websites | |
| 8,890 websites | |
| 6,767 websites | |
| 5,331 websites | |
| 3,881 websites | |
| 3,531 websites | |
| 2,891 websites | |
| 2,567 websites | |
| 2,181 websites |
| .com | 62,783 websites |
| .org | 8,821 websites |
| .de | 7,763 websites |
| .co.uk | 5,994 websites |
| .nl | 4,889 websites |
| .com.au | 3,236 websites |
| .fr | 3,191 websites |
| .net | 2,769 websites |
| .ca | 2,270 websites |
| .it | 1,924 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ****.com | *** | ||
| ****.org | *,*** | ||
| ****.ca | *,*** | ||
| **********.com | *,*** | ||
| ***********.com | *,*** | ||
| ****************.com | *,*** | ||
| ***************.org | *,*** | ||
| ****************.com | *,*** | ||
| **********.de | *,*** | ||
| ************.com | **,*** |
FAQ