CVE · High

CVE-2026-65052 — Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] <= 3.14.8 (unfixed)

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-65052 Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] <= 3.14.8 (unfixed) High 7.5 < 3.14.8 3.14.8 2026-07-21

CVE-2026-65052

The Ninja Forms WordPress plugin, versions 3.14.8 and earlier, has a vulnerability that allows attackers to manipulate form calculations and payment totals by submitting invalid input to certain field types. This can be done by exploiting a weakness in the plugin's input validation, which allows attackers to inject arbitrary numeric values into the form submission process. As a result, attackers can potentially manipulate payment amounts to zero or any other value, bypassing the intended pricing logic configured by the plugin administrator.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.