plugin

Ninja Forms Scheduled Exports Vulnerabilities

1 known security issue reported for the Ninja Forms Scheduled Exports WordPress plugin. Most recent disclosed Sep 4, 2026.

1 medium

Running Ninja Forms Scheduled Exports on your site? Check whether your installed version is affected.

Scan your site free

Ninja Forms - Scheduled Exports <= 3.0.3 - Authenticated (Subscriber+) Stored Cross-Site Scripting via REST API Parameters

medium

The Ninja Forms - Scheduled Exports plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API Parameters (interval, format, emailTo) in all versions up to, and including, 3.0.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subsc...

CVSS:
6.4
(Wordfence)
Affected:
up to 3.0.3
Fixed in:
3.0.4
Disclosed:
Sep 4, 2026

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database