DIRAS TAKE
Treat this as high priority if your public WordPress sites use the File Uploads add-on: an unauthenticated upload path can place executable files in the webroot, so disable the add-on or block write access to web-facing directories until a vendor patch is available.
What is CVE-2026-19769?
Unauthenticated attackers can store and serve malicious JavaScript from WordPress sites using the Ninja Forms plugin, enabling script execution in visitors’ browsers; this issue is tracked as CVE-2026-19769. The flaw impacts Ninja Forms 3.x (versions 3.15.1 and earlier) and depends on the Ninja Forms File Uploads add-on being active. An attacker uses the add-on’s upload handling to place attacker-controlled HTML/JS into any directory the web server can write to (including the site root), so remote access to the site and the File Uploads add-on are required for exploitation. The weakness is classified as CWE-79 (Cross-site Scripting).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Which versions of kstover Ninja Forms – The Contact Form Builder That Grows With You are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 3.x | 3.15.1 and earlier |
Is CVE-2026-19769 being exploited?
There are no public reports of exploitation as of 2026-09-30.
How to fix CVE-2026-19769
- Disable or uninstall the Ninja Forms File Uploads add-on immediately if it is not required.
- Deactivate or remove Ninja Forms plugin versions 3.15.1 and earlier, or take affected forms offline until a vendor fix is released.
- Remove webserver write permissions from the site root and upload directories; scan for unexpected HTML or script files and restore from clean backups if found.
- Monitor webserver logs and implement file-integrity monitoring; apply vendor guidance and update when a fixed version is released.
Frequently asked questions
Is CVE-2026-19769 being actively exploited?
There are no public reports of exploitation of CVE-2026-19769 as of 2026-09-30.
Which Ninja Forms versions are affected by CVE-2026-19769?
Ninja Forms 3.x releases up to and including version 3.15.1 are listed as affected.
Is there a patch for CVE-2026-19769?
No fixed version is provided in the available facts; follow the mitigations listed until the vendor issues an update.
Does CVE-2026-19769 require authentication?
No, the vulnerability can be exploited without authentication but requires the Ninja Forms File Uploads add-on to be active on the site.
References
- nvd.nist.gov/vuln/detail/CVE-2026-19769
- cve.org/CVERecord?id=CVE-2026-19769
- wordfence.com/threat-intel/vulnerabilities/id/2330e381-7db3-4b79-8827-818d2ea954b5?source=cve
- plugins.trac.wordpress.org/browser/ninja-forms/tags/3.14.11/includes/AJAX/Controllers/Submission.php#L609
- plugins.trac.wordpress.org/browser/ninja-forms/tags/3.14.11/includes/AJAX/Controllers/Submission.php#L303
- plugins.trac.wordpress.org/browser/ninja-forms/tags/3.14.11/includes/AJAX/Controllers/Submission.php#L55
- plugins.trac.wordpress.org/browser/ninja-forms/tags/3.14.11/includes/AJAX/Controllers/Submission.php#L61
- plugins.trac.wordpress.org/changeset?reponame=&new=3674413%40ninja-forms%2Ftags%2F3.15.2&old=3663678%40ninja-forms%2Ftags%2F3.15.1
- plugins.trac.wordpress.org/changeset/3674413/ninja-forms/trunk/includes/AJAX/Controllers/Submission.php
- plugins.trac.wordpress.org/changeset?old_path=%2Fninja-forms/tags/3.15.1&new_path=%2Fninja-forms/tags/3.15.2
- All kstover CVEs on CVE Radar
- CVEs published in September 2026