PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-19769 kstover CVE debrief

The Ninja Forms plugin for WordPress has a Stored Cross-Site Scripting vulnerability via Repeater Child 'type' Confusion due to insufficient input sanitization and output escaping. This allows unauthenticated attackers to inject web scripts when the Ninja Forms File Uploads add-on is active. The vulnerability exists in all versions up to, and including, 3.15.1 and exploitation requires the Ninja Forms File Uploads add-on to be active, allowing attackers to inject scripts that execute when a user accesses an injected page.

Vendor
kstover
Product
Ninja Forms – The Contact Form Builder That Grows With You
CVSS
HIGH 7.2
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-05
Original CVE updated
2026-09-08
Advisory published
2026-09-05
Advisory updated
2026-09-08

Who should care

Defenders responsible for WordPress installations using the Ninja Forms plugin should assess exposure and prioritize verification and potential updates due to the potential for unauthenticated script injection. Defenders should review compensating controls for exposed systems while remediation is scheduled and verified, and check relevant monitoring, detection, and logs for exposed assets that need extra review.

Why it matters

CVE-2026-19769 is a Stored Cross-Site Scripting vulnerability in the Ninja Forms plugin for WordPress. Defenders should prioritize verifying exposure and assessing security due to potential for unauthenticated script injection.

  • Unauthenticated attackers can inject arbitrary web scripts in pages.
  • Injected scripts execute when a user accesses an injected page.
  • Exploitation requires the Ninja Forms File Uploads add-on to be active.
  • Verify exposure and assess security of WordPress installations using the Ninja Forms plugin.

Technical summary

The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Repeater Child 'type' Confusion via Unmatched Array Key in all versions up to, and including, 3.15.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page when the Ninja Forms File Uploads add-on is active, allowing attackers to inject scripts that execute when a user accesses an injected page.

Defensive priority

Defenders should prioritize verifying exposure and assessing the security of their WordPress installations using the Ninja Forms plugin.

Recommended defensive actions

  • Verify if the Ninja Forms plugin is installed and active on WordPress installations.
  • Check if the Ninja Forms File Uploads add-on is active.
  • Assess the security of WordPress installations using the Ninja Forms plugin.
  • Consider updating to a patched version of the Ninja Forms plugin.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.

Evidence notes

The vulnerability exists in all versions up to, and including, 3.15.1 of the Ninja Forms plugin. Exploitation requires the Ninja Forms File Uploads add-on to be active. The attack routes the unwhitelisted child entry through the File Uploads handler to write an attacker-supplied HTML file containing arbitrary JavaScript into any web-server-writable directory, including the site root, where it is served from the site's own origin. Defenders should verify exposure and assess security of WordPress installations using the Ninja Forms File

Sources and references

Verified primary and authoritative sources

  • CVE-2026-19769 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-19769

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-19769 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-19769

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/ninja-forms/tags/3.14.11/includes/AJAX/Controllers/Submission.php

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/changeset/3674413/ninja-forms/trunk/includes/AJAX/Controllers/Submission.php

    [email protected]

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.