CVE-2026-91827 UNKNOWN

CVE-2026-91827

Published: 2026-09-22

Description

The Ninja Forms WordPress plugin 3.15.3 does not prevent user-submitted form field values from being deserialised when an administrator later exports form submissions to CSV, allowing unauthenticated attackers to perform PHP Object Injection; if a suitable POP chain is present via another installed plugin or theme, this can lead to actions such as arbitrary file operations or remote code execution.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…