Impact
The vulnerability resides in the Ninja Forms – Scheduled Exports add‑on for WordPress, where REST API parameters (interval, format, and emailTo) are not properly sanitized or escaped. An authenticated user with subscriber or higher privileges can store malicious scripts in the plugin’s data, which are then rendered inside pages that utilize the export data. When any user loads the affected page, the injected script executes in the user's browser, enabling data theft, session hijacking, or further attacks against that user.
Affected Systems
WordPress sites running Ninja Forms – Scheduled Exports version 3.0.3 or earlier. Any user who views a page that includes exported data can be affected if a subscriber‑level or higher account has injected malicious content.
Risk and Exploitability
The CVSS score of 6.4 positions this flaw as moderate severity. EPSS data is unavailable, so the current exploitation likelihood is uncertain. The vulnerability is not present in the CISA KEV catalog. Attackers need only authenticated access with subscriber or above privileges; the REST endpoint is accessible because it lacks a permission callback and only checks a nonce. Once exploited, the stored scripts run automatically in the browsers of any user who views the compromised page.
OpenCVE Enrichment