- Total: 4 CVEs
- Severity: 2 Critical · 2 High
- Actively exploited: None confirmed
- Highest severity: 9.3 (Critical · CVSSv3) — CVE-2026-65049
- Action: Apply the latest security updates now
Notable CVEs
| CVE | CVSS | Type | Fixed in | Status |
|---|---|---|---|---|
| CVE-2026-65049 | 9.3 | Cross-Site Network-Wide Data Deletion on WordPress Multisite via nf_delete_all_data AJAX Action | 3.14.9 | Not exploited |
| CVE-2026-65048 | 9.3 | Unauthenticated Stored Cross-Site Scripting via Repeatable Fieldset Submission Index | 3.14.9 | Not exploited |
| CVE-2026-65052 | 7.5 | Calculation and Payment Total Tampering via Fail-Open get_calc_value in ListSelect and ListRadio Fields | 3.14.9 | Not exploited |
| CVE-2026-65050 | 6.5 | Missing Authorization in submissions-table Gutenberg Block Discloses Form Submissions to Unauthenticated Visitors | 3.14.9 | Not exploited |
TL;DR
Researchers disclosed four flaws in the Ninja Forms WordPress plugin, which runs on more than 600,000 sites. The worst is a Ninja Forms vulnerability tracked as CVE-2026-65048, an unauthenticated stored XSS rated CVSS 9.3. All four are fixed in version 3.14.10.
Why it matters
Ninja Forms sits on over 600,000 active installations. A single form page can therefore expose a large audience. Two bugs need no login at all, which raises the risk sharply.
How the attacks work
CVE-2026-65048 (CVSS 9.3) is the standout. An attacker submits a public form with a crafted repeater key holding script. That script then runs in an admin’s browser when they review submissions. As a result, the attacker can steal session cookies or create rogue admin accounts.
The other three flaws differ in aim. CVE-2026-65052 (CVSS 8.7) lets attackers rewrite payment totals, even down to zero. CVE-2026-65049 (CVSS 8.4) allows a subsite admin to wipe all Ninja Forms data across a multisite network. CVE-2026-65050 (CVSS 7.1) exposes stored submissions, including names, emails and phone numbers.
Affected versions
The flaws span several branches. The stored XSS affects versions 3.10.4 through 3.14.9. The other three hit 3.14.8 and earlier.
Exploitation status
No in-the-wild exploitation has been confirmed for this Ninja Forms vulnerability set. Likewise, no public proof-of-concept code has been released so far.
Patch and mitigation
Update now to Ninja Forms 3.14.10, which patches all four issues. You can pull the fixed build directly from the official Ninja Forms 3.14.10 download package. After updating, review admin accounts and audit recent form submissions for anything unexpected.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.