Unauthenticated Stored XSS in Ninja Forms Plugin for WordPress
CVE-2026-65048
What is CVE-2026-65048?
CVE-2026-65048 is a significant vulnerability affecting the Ninja Forms plugin, utilized in WordPress to create custom forms. This vulnerability is classified as an unauthenticated stored cross-site scripting (XSS) flaw, which arises from the plugin's handling of submission indexes in the Repeatable Fieldset feature. Specifically, the issue occurs when the parseSubmissionIndex() function does not validate these indexes numerically, allowing attackers to inject arbitrary strings. This exploitation could enable unauthorized users to submit malicious scripts through a public form, which, upon being viewed by an administrator in the WordPress admin panel, would execute in the context of the admin’s browser. The consequences of this vulnerability are considerable, as it opens the door for session-cookie theft, unauthorized account creation, malicious plugin installation, and arbitrary modifications of the website’s content.
Potential impact of CVE-2026-65048
-
Session-cookie Theft: Attackers can steal session cookies from administrators, granting them unauthorized access to the WordPress admin area, potentially leading to further exploitation.
-
Creation of Unauthorized Administrator Accounts: With the ability to execute scripts in an admin's browser, attackers could create additional admin accounts, thereby increasing their control over the affected WordPress site.
-
Arbitrary Modification of Site Content: The vulnerability allows attackers to modify the site's content at will, which can lead to defacement, misinformation, or the distribution of malicious code to site visitors.
Affected Version(s)
Ninja Forms 3.10.4
Ninja Forms 3.10.4 < 3.14.9
Ninja Forms 3.14.9