CVE-2026-65048 Details
Description
Ninja Forms plugin for WordPress versions 3.10.4 through 3.14.9 contains an unauthenticated stored cross-site scripting vulnerability in the Repeatable Fieldset feature where parseSubmissionIndex() accepts arbitrary strings as submission indexes without numeric validation, and admin_form_element() interpolates the index directly into HTML without escaping. An unauthenticated attacker can submit a public form with a crafted repeater child key containing malicious script payloads, which execute in an administrator's browser when viewing submissions in the WordPress admin panel, enabling session-cookie theft, creation of administrator accounts, installation of malicious plugins, and arbitrary modification of site content.
A stored cross-site scripting vulnerability has been identified in the Ninja Forms plugin for WordPress, affecting versions 3.10.4 prior to 3.14.9. The issue arises in the Repeatable Fieldset feature, where the function parseSubmissionIndex() accepts arbitrary strings as submission indexes without proper numeric validation. This allows an unauthenticated attacker to submit a public form with a crafted repeater child key containing malicious script payloads. These scripts execute in the context of an administrator's browser when viewing submissions in the WordPress admin panel. The vulnerability could lead to session-cookie theft, unauthorized creation of administrator accounts, installation of malicious plugins, and arbitrary modification of site content.
Users can update to Ninja Forms version 3.14.9 or later to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 21, 2026CISA-ADP
Assessed Jul 21, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Ninja Forms | >= 3.10.4, <= 3.14.9 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 21, 2026 | CVE Modified | CISA-ADP |
| Jul 21, 2026 | New CVE Received | [email protected] |
Volerion