A critical stored cross-site scripting flaw, tracked as CVE-2026-65048, was disclosed in the Ninja Forms WordPress plugin. The vulnerability affects versions 3.10.4 through 3.14.9 and stems from the plugin's Repeatable Fieldset feature, where submission indexes are accepted without numeric validation and later rendered into HTML without proper escaping. Because the vulnerable input can be submitted through a public form, the issue can be exploited by an unauthenticated attacker.
A successful attack stores malicious JavaScript in form submissions and triggers execution when an administrator reviews those submissions in the WordPress admin panel. The flaw carries a CVSS 3.1 score of 9.3 and could enable session-cookie theft, administrator account creation, malicious plugin installation, and unauthorized modification of site content. Site owners using Ninja Forms are advised to upgrade to 3.15.0 or later to remediate the issue.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
A CVE entry disclosed CVE-2026-65048, a critical unauthenticated stored cross-site scripting flaw in Ninja Forms' Repeatable Fieldset feature. The issue can be triggered through crafted public form submissions and may lead to administrator compromise when submissions are viewed in the WordPress admin panel.
The WordPress plugin listing indicates Ninja Forms version 3.15.0 was published on 2026-04-24. The CVE reference states updating to 3.15.0 or later remediates the unauthenticated stored XSS vulnerability affecting versions 3.10.4 through 3.14.9.
A security advisory reported multiple Ninja Forms vulnerabilities, including the previously documented unauthenticated stored XSS issue and a network-wide data-deletion vulnerability.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
gmcsirt.gm
Open sourcecvefeed.io
Open sourcewordpress.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.