CVE-2026-65048 (matched: wordpress)

  • Tuesday, 21st July, 2026
  • 16:03pm

A security flaw has been found in the Ninja Forms plugin for WordPress, impacting versions 3.10.4 through 3.14.9. The issue is a vulnerability that lets hidden harmful code be saved with form submissions, via the plugin's Repeatable Fieldset feature used to build forms with dynamic, repeatable input sections. This flaw allows anyone, even people without an account on your website, to submit a specially crafted entry to any public form that uses this repeatable field feature. The malicious code is stored along with the form submission data. When you or another administrator on your site view these saved submissions in your WordPress admin dashboard, that hidden code runs in your browser. This could enable an attacker to steal your admin login session, create unauthorized administrator accounts, install malicious plugins on your site, or make unapproved changes to your site's content.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-65048

« Back