---
id: CVE-2026-91827
title: >-
  The Ninja Forms WordPress plugin 3.15.3 does not prevent user-submitted form
  field values from being deserialised when an administrator later exports form
  submissions to CSV, allowing unauthenticated attackers to perform PHP Object
  Injec…
summary: >-
  The Ninja Forms WordPress plugin 3.15.3 does not prevent user-submitted form
  field values from being deserialised when an administrator later exports form
  submissions to CSV, allowing unauthenticated attackers to perform PHP Object
  Injec…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-502
product: Ninja Forms
affected:
  - ninja_forms >= 3.15.3 < 3.15.4
published: '2026-09-22'
updated: '2026-09-22'
sourceUpdated: '2026-09-22T19:41:38.447'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-91827'
references:
  - url: 'https://wpscan.com/vulnerability/7b279db2-92e0-4122-b5c6-aa12b7b01858/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
epss: 0.00304
epssPercentile: 0.23405
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-22T10:05:51.795663Z'
ingestedAt: '2026-09-22T08:00:27.682Z'
---

## Overview

The Ninja Forms WordPress plugin 3.15.3 does not prevent user-submitted form field values from being deserialised when an administrator later exports form submissions to CSV, allowing unauthenticated attackers to perform PHP Object Injection; if a suitable POP chain is present via another installed plugin or theme, this can lead to actions such as arbitrary file operations or remote code execution.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
