CVE-2026-91827: Unknown Ninja Forms
High severity, CVSS 7.5. EPSS: 0.3% chance of exploitation in the next 30 days.
The Ninja Forms WordPress plugin 3.15.3 does not prevent user-submitted form field values from being deserialised when an administrator later exports form submissions to CSV, allowing unauthenticated attackers to perform PHP Object Injection; if a suitable POP chain is present via another installed plugin or theme, this can lead to actions such as arbitrary file operations or remote code execution.
Affected products
- Unknown Ninja Forms: from 3.15.3, before 3.15.4 (fixed in 3.15.4)
Published 2026-09-22. Last modified 2026-09-22.