securityonline.info 7/23/2026, 1:56:46 AM · external

600K Sites at Risk: Ninja Forms Stored XSS Flaw CVE-2026-65048 Hits CVSS 9.3

600K Sites at Risk: Ninja Forms Stored XSS Flaw CVE-2026-65048 Hits CVSS 9.3
CyberSIXT Evidence Panel
CISA KEV Not in KEV
Patch Patch Available

THE content discusses critical vulnerabilities in the Ninja Forms WordPress plugin identified as CVE-2026-65048, CVE-2026-65049, CVE-2026-65050, and CVE-2026-65052, affecting over 600,000 sites. The notably severe CVE-2026-65048 is an unauthenticated stored XSS vulnerability with a CVSS score of 9.3, allowing attackers to execute scripts in an admin's browser. All vulnerabilities are fixed in version 3.14.10. It emphasizes the urgency of updating to the latest version to mitigate risks, as no confirmed exploitation has been observed yet.

View full article

Article by CyberSIXT