Skip to content
PatchBriefing

Search PatchBriefing

Type at least two characters. Results update as you type.

Search CVEs, products, packages and article titles.

Nothing found. Identifiers such as CVE and GHSA can be searched in both languages.

Subscribe

Medium · 6.2 WordPress CVE-2026-92438 CVE-2026-91827 CVE-2026-90438 CVE-2026-95515

Ninja Forms Plugin: Four Vulnerabilities Allow Unauthenticated XSS and Object Injection Attacks

Four separate vulnerabilities in the Ninja Forms WordPress plugin (up to and including 3.15.4) allow unauthenticated attackers to inject scripts via form submissions or trigger PHP object injection, with no vendor fix confirmed for three of the four issues.

AI summary

Ninja Forms, a widely used WordPress contact form plugin, is affected by four distinct vulnerabilities disclosed in September and October 2026. All four can be triggered by unauthenticated attackers submitting data through public-facing forms, and all affect versions up to and including 3.15.3 or 3.15.4 depending on the specific issue. Three involve cross-site scripting (XSS) through insufficiently sanitized form field values, while the fourth involves PHP object injection through unsafe deserialization during CSV export. This briefing summarizes all four issues together because they share the same plugin, a similar attack surface (public form submission), and overlapping disclosure timing.

Four Separate Issues Disclosed in Ninja Forms

Four CVEs were published for the Ninja Forms WordPress plugin within roughly one week of each other (September 22–23, 2026, with one modified October 2, 2026): - CVE-2026-92438: Submitted form field values are not escaped before being displayed on the submission edit screen in the admin area, allowing stored XSS against administrators reviewing submissions. Affects version 3.15.3 and earlier, with a fix referenced in 3.15.4. - CVE-2026-91827: Form field values are not safely handled when an administrator exports submissions to CSV, allowing PHP Object Injection. Affects version 3.15.3 and earlier, with a fix referenced in 3.15.4. - CVE-2026-90438: Stored XSS via the Paragraph Text field when the Rich Text Editor (RTE) option is enabled, due to insufficient input sanitization and output escaping. Affects versions up to and including 3.15.4, with a fix referenced in 3.15.5. - CVE-2026-95515: An unauthenticated XSS issue affecting versions up to and including 3.15.3, with a fix referenced in 3.15.4. The source description for this entry does not provide further technical detail.

Insufficient Sanitization of Submitted Form Data

The common technical thread across three of the four issues (CVE-2026-92438, CVE-2026-90438, CVE-2026-95515) is a failure to properly sanitize or escape user-submitted form field values before they are rendered elsewhere — either in the admin submission review screen or on public pages. This is classified as CWE-79 (Cross-Site Scripting) in each case. CVE-2026-91827 is different in nature: it is classified as CWE-502 (Deserialization of Untrusted Data), where submitted field values are deserialized unsafely during the CSV export process used by administrators. If a Property-Oriented Programming (POP) chain is available through another installed plugin or theme, this deserialization issue could be leveraged for actions such as arbitrary file operations or remote code execution, though the fact package does not confirm that any specific POP chain exists or has been demonstrated.

Unauthenticated Attackers Can Target Administrators and Site Visitors

All four vulnerabilities can be triggered by unauthenticated attackers simply by submitting data through a public-facing Ninja Forms form — no account or login is required to initiate the attack. The impact varies by issue: the XSS vulnerabilities (CVE-2026-92438, CVE-2026-90438, CVE-2026-95515) can execute malicious scripts in the browser of a privileged user reviewing submissions, or in the browser of any visitor to an affected page. The object injection vulnerability (CVE-2026-91827) requires an administrator to export submissions to CSV and, depending on other installed software, could potentially escalate to file manipulation or remote code execution. Given that Ninja Forms is used on a large number of WordPress sites, the combined attack surface across these four issues is significant for any site exposing a public contact or submission form.

Sites Running Vulnerable Ninja Forms Versions

Any WordPress site using the Ninja Forms plugin in version 3.15.3 or earlier is affected by CVE-2026-92438, CVE-2026-91827, and CVE-2026-95515. Sites running version 3.15.4 or earlier are affected by CVE-2026-90438, and specifically by this issue only when a Paragraph Text field has the Rich Text Editor (RTE) option enabled.

Affected and Referenced Fixed Versions

- CVE-2026-92438: affects 3.15.3 and earlier; fix referenced in 3.15.4. - CVE-2026-91827: affects 3.15.3 and earlier; fix referenced in 3.15.4. - CVE-2026-90438: affects up to and including 3.15.4; fix referenced in 3.15.5. - CVE-2026-95515: affects up to and including 3.15.3; fix referenced in 3.15.4.

Fix Status Unconfirmed

The fact package lists fixed version numbers (3.15.4 for three issues, 3.15.5 for one issue) in the affected-range data, but the fix_available flag for all four advisories is marked false, and no vendor confirmation of an actual release or patch is present in the supplied data. This is a direct conflict between the referenced version numbers and the fix-availability flag. Site operators should verify directly with the plugin's changelog or official WordPress.org plugin page whether 3.15.4 and/or 3.15.5 have been released and address these specific CVEs before relying on version number alone as confirmation of a fix.

Recommended Steps

Site administrators running Ninja Forms should check their installed version against the version ranges listed above and consult the official plugin changelog to confirm whether updates addressing these CVEs have been released. Until a confirmed fix is verified, consider restricting or closely reviewing form submissions, exercising caution when reviewing submission content in the admin dashboard, and reviewing CSV exports carefully, particularly if other plugins or themes are installed that could provide a POP chain usable by CVE-2026-91827.

PatchBriefing score

6.2 / 10 · Medium

Official CVSS: 8.8

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Why this score

The four vulnerabilities carry CVSS base scores ranging from 7.1 to 8.8, reflecting network-exploitable, unauthenticated attack vectors with meaningful confidentiality and/or integrity impact. Patchwire scores (5.3 to 6.2) incorporate the CVSS base score alongside additional factors: all four issues can be triggered without authentication, none require no user interaction except CVE-2026-90438, none currently have a confirmed fix available, and all affect a plugin with substantial install base (contributing to product popularity scoring). No known exploitation in the wild or public exploit code is recorded for any of these four CVEs, and EPSS scores were not available in the source data.

Affected versions

Ninja Forms < 3.15.4
vulnerable
Ninja Forms < 3.15.4
vulnerable
Ninja Forms < 3.15.5
vulnerable
Ninja Forms < 3.15.4
vulnerable

Reported fixes

The fact package lists fixed version numbers (3.15.4 for three issues, 3.15.5 for one issue) in the affected-range data, but the fix_available flag for all four advisories is marked false, and no vendor confirmation of an actual release or patch is present in the supplied data. This is a direct conflict between the referenced version numbers and the fix-availability flag. Site operators should verify directly with the plugin's changelog or official WordPress.org plugin page whether 3.15.4 and/or 3.15.5 have been released and address these specific CVEs before relying on version number alone as confirmation of a fix.

How this was built

8 source records were collected, matched and used to prepare the report above.

  • WPVulnerability database
  • NVD (NIST) database
  • WPVulnerability database
  • NVD (NIST) database
  • WPVulnerability database
  • NVD (NIST) database
Unified report
Ninja Forms Plugin: Four Vulnerabilities Allow Unauthenticated XSS and Object Injection Attacks
1 article · 8 sources cited
Revision history
  1. Published
  2. Generated
The Morning Brief

Relevant changes for the stacks you follow.

Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.

✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email