{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/ninja-forms--3.15.1/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:ninjaforms:ninja_forms:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-19769"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Ninja Forms (\u003c= 3.15.1)"],"_cs_severities":["high"],"_cs_tags":["web-application","wordpress","xss","cve-2026-19769"],"_cs_type":"advisory","_cs_vendors":["Ninja Forms"],"content_html":"\u003cp\u003eThe Ninja Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) and arbitrary file write attacks due to insufficient input sanitization and output escaping. Affecting all versions up to and including 3.15.1, the flaw specifically involves a Repeater Child 'type' confusion triggered by an unmatched array key. Exploitation of this vulnerability requires the Ninja Forms File Uploads add-on to be active.\u003c/p\u003e\n\u003cp\u003eAttackers can manipulate the child entry handling process to force the application to write attacker-controlled HTML files containing arbitrary JavaScript into web-server-writable directories. Because these files are written to locations such as the site root, they are served directly from the site origin, enabling the execution of malicious scripts whenever an administrator or user visits the injected page. This represents a significant risk to WordPress site integrity and user session security.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn unauthenticated attacker identifies a WordPress site with the Ninja Forms plugin (version \u0026lt;= 3.15.1) and the File Uploads add-on active.\u003c/li\u003e\n\u003cli\u003eThe attacker crafts a malicious request payload targeting the Repeater Child handler in the plugin.\u003c/li\u003e\n\u003cli\u003eThe payload utilizes array key confusion to bypass existing input sanitization filters within the plugin logic.\u003c/li\u003e\n\u003cli\u003eThe request is routed through the File Uploads handler, which fails to validate the file type or destination path.\u003c/li\u003e\n\u003cli\u003eThe plugin writes an attacker-supplied HTML file containing malicious JavaScript to a web-server-writable directory on the target filesystem.\u003c/li\u003e\n\u003cli\u003eThe injected file is successfully stored in a location accessible via the web server (e.g., the site root).\u003c/li\u003e\n\u003cli\u003eA victim (typically an administrator) accesses the malicious file via the web browser.\u003c/li\u003e\n\u003cli\u003eThe browser renders the HTML file, executing the injected JavaScript in the context of the vulnerable site origin.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to execute arbitrary JavaScript in the victim's browser, potentially leading to unauthorized administrative actions, account takeover, or the exfiltration of sensitive site data. Organizations running vulnerable versions of Ninja Forms on WordPress are at risk of complete site compromise if an administrative session is hijacked via the injected scripts.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003eUpdate the Ninja Forms plugin to the latest available version beyond 3.15.1 to incorporate the necessary input sanitization fixes. Detection teams should audit web access logs for anomalous POST requests directed at the File Uploads or Repeater endpoints. If an immediate patch is not possible, disable the File Uploads add-on to mitigate the identified vector.\u003c/p\u003e\n","date_modified":"2026-09-05T07:30:37Z","date_published":"2026-09-05T07:30:37Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-19769-ninja-forms/","summary":"An unauthenticated stored XSS and arbitrary file write vulnerability in Ninja Forms versions 3.15.1 and earlier allows attackers to inject malicious scripts by exploiting input validation flaws in the File Uploads add-on.","title":"Stored XSS and Arbitrary File Write in Ninja Forms WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-19769-ninja-forms/"}],"language":"en","title":"CraftedSignal Threat Feed - Ninja Forms (\u003c= 3.15.1)","version":"https://jsonfeed.org/version/1.1"}