CVE-2026-91827
Gravedad CVSS v3.1:
ALTA
Tipo:
CWE-502
Deserialización de datos no confiables
Fecha de publicación:
22/09/2026
Última modificación:
22/09/2026
Descripción
*** Pendiente de traducción *** The Ninja Forms WordPress plugin 3.15.3 does not prevent user-submitted form field values from being deserialised when an administrator later exports form submissions to CSV, allowing unauthenticated attackers to perform PHP Object Injection; if a suitable POP chain is present via another installed plugin or theme, this can lead to actions such as arbitrary file operations or remote code execution.
Impacto
Puntuación base 3.x
7.50
Gravedad 3.x
ALTA


