Junglewise Threat Intelligence

CVE-2026-15161: SaturdayDrive Ninja Forms - Excel Export Stored XSS in save_filter

CVE-2026-15161 · Severity: medium · CVSS 6.4 · Published 2026-07-17

Technologies: SaturdayDrive Ninja Forms - Excel Export. Vendors: SaturdayDrive.

Executive brief

The Ninja Forms - Excel Export plugin for WordPress, which allows users to export form submissions to Excel files, contains a security flaw that allows low-level users to inject malicious scripts. An attacker with a basic account (such as a subscriber) can save malicious code that will execute in the browser of an administrator or other users when they visit the plugin's settings page. This could lead to unauthorized actions being performed on behalf of an administrator, potentially compromising the entire website.

Technical details

The Ninja Forms - Excel Export plugin is vulnerable to Stored Cross-Site Scripting (XSS) due to a lack of security controls in the save_filter() AJAX handler. Specifically, the handler fails to perform capability checks, nonce verification, or input sanitization before saving the $_POST['filter'] array to the database using update_option(). Furthermore, the get_filter_row() method fails to use esc_attr() when outputting these stored values (field_key, condition, and value) into HTML attributes on the admin Excel Export screen. This allows authenticated attackers with subscriber-level permissions or higher to inject arbitrary web scripts that execute in the context of an administrative user's session.

Affected products

  • SaturdayDrive Ninja Forms - Excel Export <= 3.3.6

Timeline

  • 2026-07-17: advisory: Initial advisory published by Wordfence and NVD.

References