Executive brief
Ninja Forms is a popular WordPress plugin used to create and manage website contact forms. A security flaw allows unauthorized individuals to inject malicious scripts into form submissions. If a site administrator views these submissions, the scripts can execute, potentially allowing attackers to steal login credentials, create new admin accounts, or take full control of the website.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in Ninja Forms versions 3.10.4 through 3.14.8. The root cause is a lack of numeric validation in the parseSubmissionIndex() function and a failure to escape output in the admin_form_element() function within the Repeatable Fieldset feature. An unauthenticated attacker can submit a crafted repeater child key containing a script payload via a public form. When an administrator views these submissions in the WordPress admin panel, the payload executes in their browser context. This can lead to session hijacking, unauthorized administrative account creation, or the installation of malicious plugins. The issue is fixed in version 3.14.9.
Affected products
- Saturday Drive Ninja Forms 3.10.4 - 3.14.8
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory
- 2026-07-21: patched: Fixed in version 3.14.9