High severity7.5NVD Advisory· Published Sep 22, 2026
CVE-2026-91827
CVE-2026-91827
Description
The Ninja Forms WordPress plugin 3.15.3 does not prevent user-submitted form field values from being deserialised when an administrator later exports form submissions to CSV, allowing unauthenticated attackers to perform PHP Object Injection; if a suitable POP chain is present via another installed plugin or theme, this can lead to actions such as arbitrary file operations or remote code execution.
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.