CVE-2026-102385: WordPress Ninja Forms plugin <= 3.15.3 - Cross Site Scripting (XSS) vulnerability
Unauthenticated Cross Site Scripting (XSS) in Ninja Forms <= 3.15.3 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Ninja Forms pluginto a version that resolves this vulnerability.Fixed in 3.15.5
Event History
Frequently Asked Questions
Which installations are affected?
Ninja Forms versions 3.15.3 and earlier are affected. The available information does not state whether any particular WordPress configuration or feature must be enabled.
Does exploitation require an authenticated WordPress account?
No. The vulnerability is described as unauthenticated, so an attacker does not need WordPress credentials. Exploitation does require user interaction, as indicated by the UI:R vector.
What is the potential impact if exploitation succeeds?
The assigned vector indicates low confidentiality, integrity, and availability impact, with scope changed. As an XSS issue, successful exploitation may allow attacker-controlled script to execute in a victim's browser context.