A vulnerability has been found in Ninja Forms Plugin up to 3.14.9 on WordPress and classified as problematic. Affected by this issue is the function
_save_setting/insert_form_meta of the file Model.php/ImportForm.php of the component Import Processing. The manipulation of the argument Settings leads to sql injection.
This vulnerability is traded as CVE-2026-15663. It is possible to initiate the attack remotely. There is no exploit available.