Unauthenticated Stored XSS in Ninja Forms Plugin for WordPress
CVE-2026-65048

9.3CRITICAL

Key Information:

Vendor

WordPress

Vendor
CVE Published:
21 July 2026

What is CVE-2026-65048?

The Ninja Forms plugin for WordPress versions 3.10.4 through 3.14.9 is vulnerable to an unauthenticated stored cross-site scripting (XSS) attack. This vulnerability resides in the Repeatable Fieldset feature, where the parseSubmissionIndex() function accepts unsanitized submission indexes. An attacker can exploit this flaw by submitting a public form with a maliciously crafted repeater child key, which allows arbitrary script execution in an administrator’s browser when they view submissions in the WordPress admin panel. This can lead to serious security issues, including session-cookie theft, unauthorized creation of admin accounts, installation of malicious plugins, and the modification of site content.

Affected Version(s)

Ninja Forms 3.10.4

Ninja Forms 3.10.4 < 3.14.9

Ninja Forms 3.14.9

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Pavel Kohout
.