Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 22 Sep 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ninjaforms
Ninjaforms ninja Forms Wordpress Wordpress wordpress |
|
| Weaknesses | CWE-502 | |
| Vendors & Products |
Ninjaforms
Ninjaforms ninja Forms Wordpress Wordpress wordpress |
Tue, 22 Sep 2026 07:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Ninja Forms WordPress plugin 3.15.3 does not prevent user-submitted form field values from being deserialised when an administrator later exports form submissions to CSV, allowing unauthenticated attackers to perform PHP Object Injection; if a suitable POP chain is present via another installed plugin or theme, this can lead to actions such as arbitrary file operations or remote code execution. | |
| Title | Ninja Forms 3.15.3 - Unauthenticated PHP Object Injection via CSV Export | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-09-22T06:58:01.461Z
Reserved: 2026-09-15T08:07:50.100Z
Link: CVE-2026-91827
No data.
Status : Received
Published: 2026-09-22T07:16:31.093
Modified: 2026-09-22T07:16:31.093
Link: CVE-2026-91827
No data.
OpenCVE Enrichment
Updated: 2026-09-22T08:30:17Z