---
id: CVE-2026-15550
title: >-
  The Ninja Forms - Save Progress plugin for WordPress is vulnerable to Missing
  Authorization in versions up to, and including, 3.0.30
summary: >-
  The Ninja Forms - Save Progress plugin for WordPress is vulnerable to Missing
  Authorization in versions up to, and including, 3.0.30. This is due to the
  lack of capability checks and nonce verification in the 'bulk_actions'
  function. Thi…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-862
published: '2026-09-05'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T13:12:58.310'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-15550'
references:
  - url: 'https://ninjaforms.com/extensions/save-progress/'
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/a7d3e6ce-e6d7-455b-a43d-a14189b30491?source=cve
    label: security@wordfence.com
tags:
  - nvd
epss: 0.00161
epssPercentile: 0.05744
ingestedAt: '2026-09-06T07:51:56.982Z'
---

## Overview

The Ninja Forms - Save Progress plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 3.0.30. This is due to the lack of capability checks and nonce verification in the 'bulk_actions' function. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary database records from the 'wp_nf3_objects' table, such as saved submissions.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
