CVE-2026-91827

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Ninja Forms WordPress plugin 3.15.3 does not prevent user-submitted form field values from being deserialised when an administrator later exports form submissions to CSV, allowing unauthenticated attackers to perform PHP Object Injection; if a suitable POP chain is present via another installed plugin or theme, this can lead to actions such as arbitrary file operations or remote code execution.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-09-22: 109-22
Referenced assets1 URL
Full discourse1 post
  • Severity Daily@severitydaily

    Ninja Forms deserializes an anonymous visitor's form value weeks later, when an admin exports to CSV. WPScan (@_wpscan_) calls it unauthenticated object injection. Fixed in 3.15.4. No exploitation reported. https://severitydaily.com/ninja-forms-cve-2026-91827-object-injection-csv-export-two-cnas-one-xss/

    0000019
    24 followersView on X

Explore more