Medium · 5.3 WordPress CVE-2026-102385
Unauthenticated XSS Vulnerability in Ninja Forms WordPress Plugin (CVE-2026-102385)
Ninja Forms versions up to 3.15.3 contain an unauthenticated Cross-Site Scripting (XSS) vulnerability. The plugin's advisory lists 3.15.5 as a fixed version reference, but no confirmed fix has been verified by PatchBriefing at this time.
AI summary
A Cross-Site Scripting (XSS) vulnerability has been identified in Ninja Forms, a widely used WordPress plugin for building contact forms, calculators, quizzes, and signature forms. The vulnerability, tracked as CVE-2026-102385, can be exploited by an unauthenticated attacker, though it requires some form of user interaction to trigger. This briefing summarizes what is known, who is affected, and what site owners should consider doing.
What Happened
A Cross-Site Scripting (XSS) vulnerability was identified in the Ninja Forms WordPress plugin, affecting versions up to and including 3.15.3. The issue is classified under CWE-79 (Improper Neutralization of Input During Web Page Generation). It was published on September 30, 2026, and is tracked as CVE-2026-102385.
Technical Cause
The vulnerability is an Unauthenticated Cross-Site Scripting (XSS) flaw. According to the CVSS vector (AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L), the attack can be carried out remotely over the network, requires low attack complexity, and does not require any privileges on the target system. However, it does require user interaction, meaning a victim would need to be lured into performing some action, such as clicking a malicious link, for the attack to succeed. No further technical detail about the specific injection point or affected form functionality was provided in the source material.
Why It Matters
Cross-Site Scripting vulnerabilities allow attackers to inject malicious scripts that execute in the context of a victim's browser session. Because this flaw can be triggered without authentication, any visitor to a vulnerable site could potentially be targeted, provided they are induced to interact with a malicious element. The CVSS score of 7.1 reflects a scope change (S:C), meaning the impact may extend beyond the vulnerable component itself, alongside limited confidentiality, integrity, and availability impacts (each rated Low).
Who Is Affected
Any WordPress site running the Ninja Forms plugin at version 3.15.3 or earlier is potentially affected. Ninja Forms is a popular plugin used for building contact forms, calculators, quizzes, and other interactive forms on WordPress sites, with an estimated install base in the hundreds of thousands.
Affected Versions
Versions of Ninja Forms up to and including 3.15.3 are documented as affected. Source material references 3.15.5 as the version after which the issue is addressed in the advisory title, but PatchBriefing has not been able to independently confirm the availability or contents of a fix at this time.
Fixes and Mitigation
The fact package marks this advisory as 'fix not confirmed available' (fix_available: false), despite the advisory title referencing version 3.15.5. PatchBriefing cannot confirm with certainty whether a patched release exists or what changes it may contain. Site owners should monitor the official Ninja Forms plugin changelog and the WordPress.org plugin repository for updates and verify the current installed version against any future confirmed fixed release.
Recommended Action
Site administrators running Ninja Forms should check their currently installed version and compare it against the latest version available through the WordPress plugin repository. Until a confirmed fixed version is verified, consider reviewing form-related input handling, restricting untrusted user interactions where possible, and monitoring for unusual activity related to form submissions.
PatchBriefing score
5.3 / 10 · Medium
Official CVSS: 7.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Why this score
The PatchBriefing score of 5.3 is derived primarily from the CVSS base score of 7.1, which reflects an unauthenticated, network-exploitable XSS vulnerability with low attack complexity but requiring user interaction. Additional contributing factors include the unauthenticated/remote nature of the attack vector, the lack of a confirmed available fix, and the plugin's significant install base (estimated at 500,000 installations). There is no evidence of known exploitation in the wild or public exploit code, which keeps the overall score moderate rather than critical.
Affected versions
- Ninja Forms < 3.15.5
- vulnerable
Reported fixes
The fact package marks this advisory as 'fix not confirmed available' (fix_available: false), despite the advisory title referencing version 3.15.5. PatchBriefing cannot confirm with certainty whether a patched release exists or what changes it may contain. Site owners should monitor the official Ninja Forms plugin changelog and the WordPress.org plugin repository for updates and verify the current installed version against any future confirmed fixed release.
How this was built
2 source records were collected, matched and used to prepare the report above.
-
WPVulnerability database
-
NVD (NIST) database
Revision history
- Published
- Generated
Related
Relevant changes for the stacks you follow.
Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.
✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email