Ninja Forms plugin for WordPress versions 3.10.4 through 3.14.9 contains an unauthenticated stored cross-site scripting vulnerability in the Repeatable Fieldset feature where parseSubmissionIndex() accepts arbitrary strings as submission indexes without numeric validation, and admin_form_element() interpolates the index directly into HTML without escaping. An unauthenticated attacker can submit a public form with a crafted repeater child key containing malicious script payloads, which execute in an administrator's browser when viewing submissions in the WordPress admin panel, enabling session-cookie theft, creation of administrator accounts, installation of malicious plugins, and arbitrary modification of site content.
We have discovered 91,428 live websites that are affected by CVE-2026-65048.
| Product | |
| Category | Form Builders |
| Vulnerable Domains | 91,428 live websites (72% of Ninja Forms install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 23 versions ( 9.66% of all versions) |
| 43,360 websites | |
| 8,676 websites | |
| 6,576 websites | |
| 4,664 websites | |
| 3,994 websites | |
| 2,891 websites | |
| 2,368 websites | |
| 1,712 websites | |
| 1,685 websites | |
| 1,632 websites |
| .com | 45,252 websites |
| .org | 6,827 websites |
| .de | 5,903 websites |
| .co.uk | 4,481 websites |
| .nl | 3,687 websites |
| .fr | 2,320 websites |
| .com.au | 2,180 websites |
| .net | 1,947 websites |
| .ca | 1,707 websites |
| .ch | 1,476 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ****.com | *** | ||
| ****.org | *,*** | ||
| ****.ca | *,*** | ||
| **********.com | *,*** | ||
| ***********.com | *,*** | ||
| ****************.com | *,*** | ||
| ***************.org | *,*** | ||
| **********.de | *,*** | ||
| *************.com | **,*** | ||
| ****************.com | **,*** |
FAQ