HIGH
kstover
CVE published 2026-09-05
CVE-2026-19769
The Ninja Forms plugin for WordPress has a Stored Cross-Site Scripting vulnerability via Repeater Child 'type' Confusion due to insufficient input sanitization and output escaping. This allows unauthenticated attackers to inject web scripts when the Ninja Forms File Uploads add-on is active. The vulnerability exists in all versions up to, and including, 3.15.1 and exploitation requires the Ninja Forms Fil [truncated]