Impact
The vulnerability resides in the Ninja Forms plugin for WordPress versions 3.10.4 through 3.14.9. An unauthenticated attacker can submit a public form that leverages the Repeatable Fieldset feature with a crafted child key containing malicious script. The parser parseSubmissionIndex incorrectly accepts arbitrary strings as indices, and admin_form_element interpolates the index directly into HTML without escaping, resulting in a stored cross‑site scripting flaw that executes when an administrator views the submission. The impact includes session‑cookie theft, creation of administrator accounts, installation of malicious plugins, and arbitrary modification of site content.
Affected Systems
Ninja Forms plugin within WordPress installations running any version from 3.10.4 to 3.14.9 is affected. The vulnerability does not cross vendor boundaries beyond the Ninja Forms plugin. Versions outside this range, including newer releases, are unaffected.
Risk and Exploitability
The CVSS score of 9.3 classifies this flaw as Critical. However, the EPSS score is less than 1 % and the flaw is not listed in the CISA KEV catalog, indicating a low immediate exploitation risk. The likely attack vector is an unauthenticated remote attacker who can submit the vulnerable form from any external source; the script then triggers only when an authorized administrator reviews the stored entry. While the flaw requires an admin action to realize the impact, the potential damage from a successful exploitation—session hijacking, privilege escalation, and code injection—makes it essential to address the vulnerability as soon as possible.
OpenCVE Enrichment