Stored Cross-Site Scripting Vulnerability in Ninja Forms Plugin for WordPress
CVE-2026-19769

7.2HIGH

What is CVE-2026-19769?

The Ninja Forms plugin for WordPress is susceptible to Stored Cross-Site Scripting. This vulnerability arises from a failure in proper input sanitization and output escaping affecting all versions up to 3.15.1. Attackers can exploit this flaw via the Repeater Child 'type' Confusion, allowing them to inject arbitrary web scripts that execute when users access affected pages. Exploitation is facilitated by the active Ninja Forms File Uploads add-on, which improperly handles unwhitelisted child entries, permitting the injection of malicious HTML files into vulnerable directories on the server.

Affected Version(s)

Ninja Forms – The Contact Form Builder That Grows With You 0 <= 3.15.1

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jonah Burgess (CryptoCat)
.