PT-2026-60709 · Saturday Drive+1 · Ninja Forms - Excel Export

CVE-2026-15161

·

Published

2026-07-16

·

Updated

2026-07-17

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Ninja Forms - Excel Export versions prior to 3.3.7
Description Stored Cross-Site Scripting occurs when the save filter() AJAX handler stores the raw filter array from the $ POST request into a WordPress option using update option() without performing capability checks, nonce verification, or input sanitization. Subsequently, the get filter row() method on the admin Excel Export screen concatenates the stored field key, condition, and value directly into HTML attributes without using esc attr(). This allows authenticated attackers with subscriber-level access or higher to inject arbitrary web scripts that execute when a user accesses the affected page.
Recommendations Update to a version newer than 3.3.6.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-15161

Affected Products

Ninja Forms - Excel Export