Sceawere

Vulnerability Detail

CVE-2026-102385UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Unauthenticated XSS in Ninja Forms

Vulnerability Metadata

Severity
High
Score / CVSS
7.1
Creation Date
3h ago
Vendor
Kevin Stover
Product
Ninja Forms
Attack Type
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

Unauthenticated Cross Site Scripting (XSS) in Ninja Forms <= 3.15.3 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.1",
  "pubDate": "2026-09-30T13:17:17.107Z",
  "pubdate": "2026-09-30T13:17:17.107Z",
  "executiveSummary": "This vulnerability is classified as an Unauthenticated Stored or Reflected Cross-Site Scripting (XSS) vulnerability affecting Ninja Forms versions 3.15.3 and below.\nThe flaw exists within the plugin's input handling mechanisms, allowing an unauthenticated attacker to inject malicious JavaScript into the web application context.\nSuccessful exploitation permits the execution of unauthorized scripts in the browser of any user viewing the affected page, including administrators.\nThe impact includes session hijacking, unauthorized actions performed on behalf of legitimate users, and the potential exfiltration of sensitive data or administrative credentials.\nBecause the vulnerability does not require authentication, it poses a significant risk to the integrity and confidentiality of the WordPress installation.\nThe risk is categorized as high due to the ease of exploitation, which requires only the ability to reach the vulnerable endpoint, and the potential for complete compromise of user sessions.",
  "technicalDetails": "The vulnerability resides in the way Ninja Forms processes user-supplied input before rendering it in the browser. In versions 3.15.3 and earlier, the plugin failed to implement adequate sanitization or output encoding on specific form fields or administrative views.\nThe root cause is the improper handling of user-controllable input, which allows for the injection of arbitrary HTML or JavaScript sequences. When an attacker submits a crafted payload through an entry field, the application stores or reflects this data without validating its structural integrity.\nAttack flow typically involves the attacker identifying a vulnerable entry point—such as a form field that is subsequently displayed in an administrative dashboard or a public-facing response page. The attacker injects a JavaScript payload (e.g., <script>alert(document.cookie)</script>) into the input field.\nOnce the payload is saved or reflected, the malicious script is executed by the browser of the victim upon accessing the affected page. Because the execution occurs within the context of the user's session, the script inherits the user's permissions, including those of an administrator if the data is displayed in the back-end dashboard.\nThe vulnerability requires no prior authentication, meaning an attacker can trigger the malicious code from any network location capable of reaching the target host's form submission endpoints.\nPost-exploitation impact is severe. An attacker can leverage the XSS to perform CSRF attacks, manipulate form settings, redirect users to malicious domains, or steal session cookies to bypass authentication mechanisms. This level of access often facilitates complete administrative takeover of the WordPress instance if the payload targets an administrator session."
}
CVE-2026-102385: Unauthenticated XSS in Ninja Forms (HIGH Severity, CVSS: 7.1) | Sceawere