What is CVE-2026-15663?
CVE-2026-15663 is an SQL injection vulnerability in the Ninja Forms plugin for WordPress (up to 3.14.9), exploitable via the 'settings' key in the Import File feature due to insufficient input escaping and query preparation. Attackers can manipulate database queries without authentication. Update to the latest plugin version immediately.
Azərbaycanca: CVE-2026-15663, WordPress üçün Ninja Forms plaginində (3.14.9 və əvvəlki versiyalar) İmport Faylı funksiyasındakı 'settings' açarı vasitəsilə SQL injection zəifliyidir. Bu, autentifikasiya olunmamış hücumçulara verilənlər bazasına müdaxilə etməyə imkan verir. Plaginin son versiyasına yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-89
FAQ1
What plugin is affected by the CVE-2026-15663 vulnerability?
The vulnerability is found in the Ninja Forms plugin for WordPress, version 3.14.9 and below.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.