CVE-2026-92438 PUBLISHED

Ninja Forms 3.15.3 - Unauthenticated Stored XSS via Paragraph Text Field in Submissions Admin

Assigner: WPScan
Reserved: 16.09.2026 Published: 22.09.2026 Updated: 22.09.2026

The Ninja Forms WordPress plugin 3.15.3 does not escape submitted form field values before outputting them on the submission edit screen in the admin area, which could allow unauthenticated users to submit values through a public form that then execute in the browser of any high-privileged user who reviews the submission.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS Score: 8.8

Product Status

Vendor Unknown
Product Ninja Forms
Versions Default: unaffected
  • affected from 3.15.3 to 3.15.4 (excl.)

Credits

  • Venkateswara Reddy Challa finder
  • WPScan coordinator

References

Problem Types

  • CWE-79 Cross-Site Scripting (XSS) CWE