Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 22 Sep 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 22 Sep 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ninjaforms
Ninjaforms ninja Forms Wordpress Wordpress wordpress |
|
| Weaknesses | CWE-502 | |
| Vendors & Products |
Ninjaforms
Ninjaforms ninja Forms Wordpress Wordpress wordpress |
Tue, 22 Sep 2026 07:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Ninja Forms WordPress plugin 3.15.3 does not prevent user-submitted form field values from being deserialised when an administrator later exports form submissions to CSV, allowing unauthenticated attackers to perform PHP Object Injection; if a suitable POP chain is present via another installed plugin or theme, this can lead to actions such as arbitrary file operations or remote code execution. | |
| Title | Ninja Forms 3.15.3 - Unauthenticated PHP Object Injection via CSV Export | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-09-22T10:05:56.864Z
Reserved: 2026-09-15T08:07:50.100Z
Link: CVE-2026-91827
Updated: 2026-09-22T10:05:43.776Z
Status : Received
Published: 2026-09-22T07:16:31.093
Modified: 2026-09-22T11:17:26.140
Link: CVE-2026-91827
No data.
OpenCVE Enrichment
Updated: 2026-09-22T08:30:17Z
-
CWE-502
Deserialization of Untrusted Data