Impact
An unauthenticated Cross Site Scripting vulnerability allows an attacker to inject arbitrary client‑side scripts that run with the privileges of any user who views a vulnerable form. This can lead to session hijacking, theft of authentication cookies, or site defacement, and is associated with CWE-79.
Affected Systems
The vulnerability affects WordPress sites running the Ninja Forms plugin version 3.15.3 or earlier. The vendor, Kevin Stover, released an update in 3.15.5 that removes the flaw.
Risk and Exploitability
The CVSS score of 7.1 indicates moderate to high risk, while the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. Because the flaw is unauthenticated and can be triggered via form input, an attacker does not need privileged access; forgery of form data is sufficient to execute arbitrary JavaScript on the victim’s browser.
OpenCVE Enrichment