Executive brief
Ninja Forms is a popular WordPress plugin used to create contact and payment forms. A security flaw allows unauthenticated users to bypass price settings and manually set their own payment totals, potentially reducing costs to zero. This could lead to significant financial loss for businesses using the plugin to process orders or donations.
Technical details
An improper input validation vulnerability (CWE-472) exists in Ninja Forms versions 3.14.8 and prior. The flaw resides in the get_calc_value() method, which fails open when processing ListSelect or ListRadio fields. An unauthenticated remote attacker can tamper with form submission payloads sent to the AJAX submit endpoint by providing values that do not match any pre-configured options. This causes the plugin to accept attacker-controlled numeric values for calculations, allowing for the manipulation of payment totals. The issue is fixed in version 3.14.9.
Affected products
- Saturday Drive Ninja Forms <= 3.14.8
Timeline
- 2026-07-21: advisory
- 2026-07-21: disclosed
- 2026-07-21: patched: Fixed in version 3.14.9