CVE-2026-19769: stored cross-site scripting in kstover Ninja Forms – The Contact Form Builder That Grows With You

Unauthenticated attackers can store and serve malicious JavaScript from WordPress sites using the Ninja Forms plugin, enabling script execution in visitors’ browsers; this issue is tracked as CVE-2026-19769. The flaw impacts Ninja Forms 3.x (versions 3.15.1 and earlier) and depends on the Ninja Forms File Uploads add-on being active. An attacker uses the add-on’s upload handling to place attacker-controlled HTML/JS into any directory the web server can write to (including the site root), so remote access to the site and the File Uploads add-on are required for exploitation.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
7.2HIGH
EPSS
0.00247
CWE
CWE-79
KEV DUE DATE
Not listed
PATCH
Not yet

DIRAS TAKE

Treat this as high priority if your public WordPress sites use the File Uploads add-on: an unauthenticated upload path can place executable files in the webroot, so disable the add-on or block write access to web-facing directories until a vendor patch is available.

What is CVE-2026-19769?

Unauthenticated attackers can store and serve malicious JavaScript from WordPress sites using the Ninja Forms plugin, enabling script execution in visitors’ browsers; this issue is tracked as CVE-2026-19769. The flaw impacts Ninja Forms 3.x (versions 3.15.1 and earlier) and depends on the Ninja Forms File Uploads add-on being active. An attacker uses the add-on’s upload handling to place attacker-controlled HTML/JS into any directory the web server can write to (including the site root), so remote access to the site and the File Uploads add-on are required for exploitation. The weakness is classified as CWE-79 (Cross-site Scripting).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N

Which versions of kstover Ninja Forms – The Contact Form Builder That Grows With You are affected?

BRANCHAFFECTEDFIXED
3.x3.15.1 and earlier

Is CVE-2026-19769 being exploited?

There are no public reports of exploitation as of 2026-09-30.

How to fix CVE-2026-19769

  1. Disable or uninstall the Ninja Forms File Uploads add-on immediately if it is not required.
  2. Deactivate or remove Ninja Forms plugin versions 3.15.1 and earlier, or take affected forms offline until a vendor fix is released.
  3. Remove webserver write permissions from the site root and upload directories; scan for unexpected HTML or script files and restore from clean backups if found.
  4. Monitor webserver logs and implement file-integrity monitoring; apply vendor guidance and update when a fixed version is released.

Frequently asked questions

Is CVE-2026-19769 being actively exploited?

There are no public reports of exploitation of CVE-2026-19769 as of 2026-09-30.

Which Ninja Forms versions are affected by CVE-2026-19769?

Ninja Forms 3.x releases up to and including version 3.15.1 are listed as affected.

Is there a patch for CVE-2026-19769?

No fixed version is provided in the available facts; follow the mitigations listed until the vendor issues an update.

Does CVE-2026-19769 require authentication?

No, the vulnerability can be exploited without authentication but requires the Ninja Forms File Uploads add-on to be active on the site.

References