Junglewise Threat Intelligence

CVE-2026-65052: Saturday Drive Ninja Forms improper input validation in form calculations

CVE-2026-65052 · Severity: high · CVSS 7.5 · Published 2026-07-21

Technologies: Saturday Drive Ninja Forms. Vendors: Saturday Drive.

Executive brief

Ninja Forms is a popular WordPress plugin used to create contact and payment forms. A security flaw allows unauthenticated users to bypass price settings and manually set their own payment totals, potentially reducing costs to zero. This could lead to significant financial loss for businesses using the plugin to process orders or donations.

Technical details

An improper input validation vulnerability (CWE-472) exists in Ninja Forms versions 3.14.8 and prior. The flaw resides in the get_calc_value() method, which fails open when processing ListSelect or ListRadio fields. An unauthenticated remote attacker can tamper with form submission payloads sent to the AJAX submit endpoint by providing values that do not match any pre-configured options. This causes the plugin to accept attacker-controlled numeric values for calculations, allowing for the manipulation of payment totals. The issue is fixed in version 3.14.9.

Affected products

  • Saturday Drive Ninja Forms <= 3.14.8

Timeline

  • 2026-07-21: advisory
  • 2026-07-21: disclosed
  • 2026-07-21: patched: Fixed in version 3.14.9

References

Related threats