Ninja Forms plugin for WordPress versions 3.10.4 through...
Critical severity
Unreviewed
Published
Jul 21, 2026
to the GitHub Advisory Database
•
Updated Jul 21, 2026
Description
Published by the National Vulnerability Database
Jul 21, 2026
Published to the GitHub Advisory Database
Jul 21, 2026
Last updated
Jul 21, 2026
Ninja Forms plugin for WordPress versions 3.10.4 through 3.14.9 contains an unauthenticated stored cross-site scripting vulnerability in the Repeatable Fieldset feature where parseSubmissionIndex() accepts arbitrary strings as submission indexes without numeric validation, and admin_form_element() interpolates the index directly into HTML without escaping. An unauthenticated attacker can submit a public form with a crafted repeater child key containing malicious script payloads, which execute in an administrator's browser when viewing submissions in the WordPress admin panel, enabling session-cookie theft, creation of administrator accounts, installation of malicious plugins, and arbitrary modification of site content.
References