A critical stored cross-site scripting flaw, tracked as CVE-2026-65048, was disclosed in the Ninja Forms WordPress plugin. The vulnerability affects versions 3.10.4 through 3.14.9 and stems from the plugin's Repeatable Fieldset feature, where submission indexes are accepted without numeric validation and later rendered into HTML without proper escaping. Because the vulnerable input can be submitted through a public form, the issue can be exploited by an unauthenticated attacker.
A successful attack stores malicious JavaScript in form submissions and triggers execution when an administrator reviews those submissions in the WordPress admin panel. The flaw carries a CVSS 3.1 score of 9.3 and could enable session-cookie theft, administrator account creation, malicious plugin installation, and unauthorized modification of site content. Site owners using Ninja Forms are advised to upgrade to 3.15.0 or later to remediate the issue.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
A CVE entry disclosed CVE-2026-65048, a critical unauthenticated stored cross-site scripting flaw in Ninja Forms' Repeatable Fieldset feature. The issue can be triggered through crafted public form submissions and may lead to administrator compromise when submissions are viewed in the WordPress admin panel.
The WordPress plugin listing indicates Ninja Forms version 3.15.0 was published on 2026-04-24. The CVE reference states updating to 3.15.0 or later remediates the unauthenticated stored XSS vulnerability affecting versions 3.10.4 through 3.14.9.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcewordpress.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.