Improper Input Validation in Ninja Forms Plugin by WordPress
CVE-2026-65052

8.7HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
21 July 2026

What is CVE-2026-65052?

The Ninja Forms WordPress plugin, specifically versions 3.14.8 and earlier, is vulnerable to a flaw that allows unauthenticated attackers to manipulate form calculations and payment totals. By injecting arbitrary numeric values into ListSelect or ListRadio fields, attackers can submit malicious payloads to the ajax submit endpoint. This vulnerability can cause the get_calc_value() method to fail open, potentially allowing attackers to return their controlled values and bypass configured pricing logic, which may result in unauthorized manipulation of payment amounts.

Affected Version(s)

Ninja Forms 0

Ninja Forms 0 < 3.14.9

Ninja Forms 3.14.9

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Pavel Kohout
.