CVE-2026-65052
The Ninja Forms WordPress plugin, versions 3.14.8 and earlier, has a vulnerability that allows attackers to manipulate form calculations and payment totals by submitting invalid input to certain field types. This can be done by exploiting a weakness in the plugin's input validation, which allows attackers to inject arbitrary numeric values into the form submission process. As a result, attackers can potentially manipulate payment amounts to zero or any other value, bypassing the intended pricing logic configured by the plugin administrator.
Based on public CVE data (MITRE/NVD).