A security flaw, tracked as CVE-2026-65049, exists in the Ninja Forms plugin for WordPress Multisite, impacting all versions up to and including 3.14.8. The vulnerability stems from incorrect permission checks when the plugin runs certain data management routines on multisite networks.
This issue allows a regular administrator of one individual site within a WordPress Multisite network to delete all Ninja Forms data—including form entries, custom form settings, and related stored information—from every site across the entire network, even if they do not have full network-wide admin access. An attacker could trigger this by sending a specially crafted request to the site's admin-ajax.php endpoint, using a security token that only grants access to their own individual site.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-65049