Improper Input Validation in Ninja Forms Plugin by WordPress
CVE-2026-65052
8.7HIGH
What is CVE-2026-65052?
The Ninja Forms WordPress plugin, specifically versions 3.14.8 and earlier, is vulnerable to a flaw that allows unauthenticated attackers to manipulate form calculations and payment totals. By injecting arbitrary numeric values into ListSelect or ListRadio fields, attackers can submit malicious payloads to the ajax submit endpoint. This vulnerability can cause the get_calc_value() method to fail open, potentially allowing attackers to return their controlled values and bypass configured pricing logic, which may result in unauthorized manipulation of payment amounts.
Affected Version(s)
Ninja Forms 0
Ninja Forms 0 < 3.14.9
Ninja Forms 3.14.9