CVE-2026-94504 PUBLISHED

Ninja Forms – The Contact Form Builder That Grows With You <= 3.15.3 - Stored Cross-Site Scripting

Assigner: Wordfence
Reserved: 21.09.2026 Published: 22.09.2026 Updated: 22.09.2026

Ninja Forms 3.15.3 stores an anonymous non-RTE textarea value and renders it without safe HTML encoding in the legacy submission editor. An attacker can break out of the textarea with stored script. When an Administrator opens the attacker-known direct submission URL, the script runs in the WordPress admin origin.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
CVSS Score: 7.2

Product Status

Vendor kstover
Product Ninja Forms – Contact Form Builder with Calculators, Quizzes, Signatures & AI Form Builder
Versions Default: unaffected
  • affected from 0 to 3.15.3 (incl.)

Credits

  • Hippolyte Quéré (Hippie) (Hippie) finder

References

Problem Types

  • CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CWE