ZeroHour

CVE-2026-81772

niche

Unauthenticated PHP Object Injection in Ninja Forms - Layout & Styles (<= 3.0.31)

CVSS 3.1
8.8 high
EPSS
<1%p24
Published
()
Modified
AI analysis

CVE-2026-81772 is an unauthenticated PHP object injection vulnerability (CWE-502, insecure deserialization of untrusted data) in the Ninja Forms - Layout & Styles WordPress plugin, affecting all versions up to and including 3.0.31. An unauthenticated attacker can supply a crafted serialized PHP payload that the plugin deserializes; the CVSS vector's UI:R component indicates that some form of user interaction (e.g., a victim loading an attacker-crafted request or link) is part of the exploitation path. Successful injection can chain into the broader WordPress gadget landscape, and the 8.8 (high) score with high confidentiality, integrity, and availability impacts implies potential arbitrary code execution, database manipulation, or full site compromise. Only WordPress sites running Ninja Forms - Layout & Styles version 3.0.31 or older are affected. There is no public proof-of-concept, the flaw is not in CISA's KEV, and EPSS estimates only a 0.3% probability of exploitation within 30 days, so no in-the-wild exploitation is currently known.

What to do: Update Ninja Forms - Layout & Styles to a release newer than 3.0.31 as soon as a patched version is published; if no fixed release is available yet, deactivate the plugin until one ships. Until patched, check for signs of compromise typical of PHP object injection, such as unexpected administrator accounts, modified posts or options, and unusual requests targeting the plugin's endpoints. No workaround beyond patching or disabling the plugin is documented in the available data.

Affected
Ninja Forms - Layout & Styles (WordPress plugin)<= 3.0.31
Estimated exposure
nichelikely on the order of a few thousand WordPress sites (estimate; this is a niche companion add-on and no active-install count was provided) — The plugin is a small companion add-on to Ninja Forms (a form builder whose core plugin has hundreds of thousands of installs), and add-ons of this type typically run on only a small fraction of the parent plugin's user base; no…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Unauthenticated PHP Object Injection in Ninja Forms - Layout & Styles <= 3.0.31 versions.

Ecosystems
WordPress
Weakness
CWE-502
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.