{"id":"CVE-2026-91827","title":"The Ninja Forms WordPress plugin 3.15.3 does not prevent user-submitted form field values from being deserialised when an administrator later exports form submissions to CSV, allowing unauthenticated attackers to perform PHP Object Injec…","summary":"The Ninja Forms WordPress plugin 3.15.3 does not prevent user-submitted form field values from being deserialised when an administrator later exports form submissions to CSV, allowing unauthenticated attackers to perform PHP Object Injec…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","cwe":["CWE-502"],"product":"Ninja Forms","affected":["ninja_forms >= 3.15.3 < 3.15.4"],"published":"2026-09-22","updated":"2026-09-22","sourceUpdated":"2026-09-22T19:41:38.447","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-91827","references":[{"url":"https://wpscan.com/vulnerability/7b279db2-92e0-4122-b5c6-aa12b7b01858/","label":"contact@wpscan.com"}],"tags":["nvd","cve.org"],"epss":0.00304,"epssPercentile":0.23401,"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-09-22T10:05:51.795663Z"},"ingestedAt":"2026-09-22T08:00:27.682Z","slug":"CVE-2026-91827","body":"## Overview\n\nThe Ninja Forms WordPress plugin 3.15.3 does not prevent user-submitted form field values from being deserialised when an administrator later exports form submissions to CSV, allowing unauthenticated attackers to perform PHP Object Injection; if a suitable POP chain is present via another installed plugin or theme, this can lead to actions such as arbitrary file operations or remote code execution.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}