Unauthenticated Stored XSS in Ninja Forms Plugin for WordPress
CVE-2026-65048
What is CVE-2026-65048?
The Ninja Forms plugin for WordPress versions 3.10.4 through 3.14.9 is vulnerable to an unauthenticated stored cross-site scripting (XSS) attack. This vulnerability resides in the Repeatable Fieldset feature, where the parseSubmissionIndex() function accepts unsanitized submission indexes. An attacker can exploit this flaw by submitting a public form with a maliciously crafted repeater child key, which allows arbitrary script execution in an administrator’s browser when they view submissions in the WordPress admin panel. This can lead to serious security issues, including session-cookie theft, unauthorized creation of admin accounts, installation of malicious plugins, and the modification of site content.
Affected Version(s)
Ninja Forms 3.10.4
Ninja Forms 3.10.4 < 3.14.9
Ninja Forms 3.14.9