Impact
Unauthenticated input sanitization flaws in Ninja Forms plugin up to version 3.15.3 allow a remote attacker to inject malicious script into stored form data. The injected code can run in the browser of any user visiting a form editor or a page containing the form, potentially enabling defacement, credential theft, or further social‑engineering attacks.
Affected Systems
The vulnerability resides in the WordPress Ninja Forms plugin developed by Kevin Stover. All WordPress sites running Ninja Forms 3.15.3 or earlier are impacted; newer releases, beginning with 3.15.4, contain the fix.
Risk and Exploitability
With a CVSS score of 7.1, this flaw is considered high‑severity. The EPSS score is currently unavailable and the issue is not listed in CISA KEV, but the lack of authentication barriers makes exploitation easy for anyone with access to the site. Attackers could deliver arbitrary JavaScript via form fields, which would execute in the context of site visitors, extending the potential damage from defacement to session hijacking or malicious redirects.
OpenCVE Enrichment