Stored Cross-Site Scripting Vulnerability in Ninja Forms Plugin for WordPress
CVE-2026-19769
7.2HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 5 September 2026
What is CVE-2026-19769?
The Ninja Forms plugin for WordPress is susceptible to Stored Cross-Site Scripting. This vulnerability arises from a failure in proper input sanitization and output escaping affecting all versions up to 3.15.1. Attackers can exploit this flaw via the Repeater Child 'type' Confusion, allowing them to inject arbitrary web scripts that execute when users access affected pages. Exploitation is facilitated by the active Ninja Forms File Uploads add-on, which improperly handles unwhitelisted child entries, permitting the injection of malicious HTML files into vulnerable directories on the server.
Affected Version(s)
Ninja Forms β The Contact Form Builder That Grows With You 0 <= 3.15.1