Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-65048: Ninja Forms Malicious Script Execution via Public Form Submission

CVE-2026-65048 · published 2 months ago
Summary

The Ninja Forms plugin for WordPress has a security flaw that allows an attacker to inject malicious code into an administrator's browser. This could potentially allow the attacker to steal sensitive information, create new administrator accounts, install malicious software, or modify site content. Update Ninja Forms to the latest version to fix this issue.

What to do
  • Update saturday drive ninja forms to version 3.14.9 or later.
Affected software
VendorProductAffected versions
saturday drive ninja forms < 3.14.9
Original advisory text
Ninja Forms Unauthenticated Stored Cross-Site Scripting via Repeatable Fieldset Submission Index
Ninja Forms plugin for WordPress versions 3.10.4 through 3.14.9 contains an unauthenticated stored cross-site scripting vulnerability in the Repeatable Fieldset feature where parseSubmissionIndex() accepts arbitrary strings as submission indexes without numeric validation, and admin_form_element() interpolates the index directly into HTML without escaping. An unauthenticated attacker can submit a public form with a crafted repeater child key containing malicious script payloads, which execute in an administrator's browser when viewing submissions in the WordPress admin panel, enabling session-cookie theft, creation of administrator accounts, installation of malicious plugins, and arbitrary modification of site content.
Severity
9.3 Critical
CVSS 3.1: 9.3 (NVD)
CVSS 4.0: 9.3 (NVD)
Exploitation
EPSS <1%
Type
CWE-79Cross-site Scripting (XSS)
Timeline
Published21 Jul 2026
Updated25 Sep 2026
First seen21 Jul 2026
Sources
CVE-2026-65048 · MITRE
Track software like this
Free during beta