{"id":"CVE-2026-91827","published":"2026-09-22T07:16:31.093","lastModified":"2026-09-22T07:16:31.093","description":"The Ninja Forms WordPress plugin 3.15.3 does not prevent user-submitted form field values from being deserialised when an administrator later exports form submissions to CSV, allowing unauthenticated attackers to perform PHP Object Injection; if a suitable POP chain is present via another installed plugin or theme, this can lead to actions such as arbitrary file operations or remote code execution.","cvssScore":7.5,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","cwes":[],"vendors":[],"products":[],"references":[{"url":"https://wpscan.com/vulnerability/7b279db2-92e0-4122-b5c6-aa12b7b01858/","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}