CVE-2026-81772
nicheUnauthenticated PHP Object Injection in Ninja Forms - Layout & Styles (<= 3.0.31)
CVE-2026-81772 is an unauthenticated PHP object injection vulnerability (CWE-502, insecure deserialization of untrusted data) in the Ninja Forms - Layout & Styles WordPress plugin, affecting all versions up to and including 3.0.31. An unauthenticated attacker can supply a crafted serialized PHP payload that the plugin deserializes; the CVSS vector's UI:R component indicates that some form of user interaction (e.g., a victim loading an attacker-crafted request or link) is part of the exploitation path. Successful injection can chain into the broader WordPress gadget landscape, and the 8.8 (high) score with high confidentiality, integrity, and availability impacts implies potential arbitrary code execution, database manipulation, or full site compromise. Only WordPress sites running Ninja Forms - Layout & Styles version 3.0.31 or older are affected. There is no public proof-of-concept, the flaw is not in CISA's KEV, and EPSS estimates only a 0.3% probability of exploitation within 30 days, so no in-the-wild exploitation is currently known.
What to do: Update Ninja Forms - Layout & Styles to a release newer than 3.0.31 as soon as a patched version is published; if no fixed release is available yet, deactivate the plugin until one ships. Until patched, check for signs of compromise typical of PHP object injection, such as unexpected administrator accounts, modified posts or options, and unusual requests targeting the plugin's endpoints. No workaround beyond patching or disabling the plugin is documented in the available data.
| Ninja Forms - Layout & Styles (WordPress plugin) | <= 3.0.31 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Unauthenticated PHP Object Injection in Ninja Forms - Layout & Styles <= 3.0.31 versions.
- Ecosystems
- WordPress
- Weakness
- CWE-502
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.