Impact
The vulnerability involves an unsanitized output of form field values on the submissions edit screen. An attacker can submit malicious JavaScript through a public form, which is later executed in the browser of any high‑privileged administrator who views the submission. This allows arbitrary code execution within the administrator’s session, potentially granting full control over the site. The weakness is a classic stored cross‑site scripting flaw.
Affected Systems
Ninja Forms WordPress plugin, version 3.15.3 is impacted. Any WordPress site running this version with the vulnerable plugin is susceptible to the flaw.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity. Exploitation requires the capability to submit a public form, which is trivial and does not require authentication. Since the flaw is stored and reflected in the admin interface, any administrator who views the submission can execute the payload. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, but the high CVSS combined with the easy attack path makes it a significant risk.
OpenCVE Enrichment